๐Ÿ” CVE Alert

CVE-2026-44359

CRITICAL 10.0

Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow

CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it with access to repository secrets and elevated GITHUB_TOKEN permissions. No approval gate exists. Pull requests from external users with author_association: "NONE" triggered the CI workflow automatically. The workflow directly executes attacker-controlled files from the fork checkout. This issue could have resulted in supply chain compromise, self-hosted runner compromise, and/or repository takeover for the repo. This issue is separate from GHSA-6mwm-v2vv-pp96, which addressed a command injection via github.head_ref in the setup job of the same workflow. That fix correctly moved to environment variables. However, the more critical fork checkout vulnerability across the check, build, and build-debian-src jobs was not addressed. Version 2.7.21.1370b23 contains a patch for thie issue.

CWE CWE-94 CWE-829
Vendor meshtastic
Product firmware
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for meshtastic firmware

Be the first to know when new critical vulnerabilities affecting meshtastic firmware are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

meshtastic / firmware
< 2.7.21.1370b23

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/meshtastic/firmware/security/advisories/GHSA-mjx5-98jq-q736 github.com: https://github.com/meshtastic/firmware/security/advisories/GHSA-6mwm-v2vv-pp96 github.com: https://github.com/meshtastic/firmware/commit/5716aeba3bc1e1d34fba9567ff88917ede4a78a5 drive.google.com: https://drive.google.com/file/d/1GdHT2s5hMYCiHt4zrWt1q58mvL7WQC0M/view?usp=sharing