CVE-2026-47690
MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workflow
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration of `GITHUB_TOKEN` with write permissions to the repository. The vulnerable workflow used pull_request_target, which runs in the context of the base repository with access to secrets. Commit 923820de8f64d753951fbbd54f7282a3d5f75173 fixes the issue. No known workarounds are available.
| CWE | CWE-77 CWE-1336 |
| Vendor | meltano |
| Product | hub |
| Published | Jul 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for meltano hub
Be the first to know when new high vulnerabilities affecting meltano hub are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected Versions
meltano / hub
< 923820de8f64d753951fbbd54f7282a3d5f75173
References
github.com: https://github.com/meltano/hub/security/advisories/GHSA-wrpf-f35c-j28w github.com: https://github.com/meltano/hub/pull/2247 github.com: https://github.com/meltano/hub/pull/2249 github.com: https://github.com/meltano/hub/pull/2251 github.com: https://github.com/meltano/hub/commit/923820de8f64d753951fbbd54f7282a3d5f75173 github.com: https://github.com/myogahunter/meltano-hub-poc