๐Ÿ” CVE Alert

CVE-2026-47690

HIGH 7.5

MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workflow

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration of `GITHUB_TOKEN` with write permissions to the repository. The vulnerable workflow used pull_request_target, which runs in the context of the base repository with access to secrets. Commit 923820de8f64d753951fbbd54f7282a3d5f75173 fixes the issue. No known workarounds are available.

CWE CWE-77 CWE-1336
Vendor meltano
Product hub
Published Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for meltano hub

Be the first to know when new high vulnerabilities affecting meltano hub are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

meltano / hub
< 923820de8f64d753951fbbd54f7282a3d5f75173

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/meltano/hub/security/advisories/GHSA-wrpf-f35c-j28w github.com: https://github.com/meltano/hub/pull/2247 github.com: https://github.com/meltano/hub/pull/2249 github.com: https://github.com/meltano/hub/pull/2251 github.com: https://github.com/meltano/hub/commit/923820de8f64d753951fbbd54f7282a3d5f75173 github.com: https://github.com/myogahunter/meltano-hub-poc