CVE-2026-55094
Taskcluster: Unauthenticated remote code execution in `web-server` via GraphQL `filter` argument (sift `$where`)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0.
| CWE | CWE-20 CWE-94 CWE-95 CWE-250 CWE-306 |
| Vendor | taskcluster |
| Product | taskcluster |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for taskcluster taskcluster
Be the first to know when new unknown vulnerabilities affecting taskcluster taskcluster are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
taskcluster / taskcluster
< 100.3.0
References
github.com: https://github.com/taskcluster/taskcluster/security/advisories/GHSA-ccv5-c45x-2q38 github.com: https://github.com/taskcluster/taskcluster/issues/8716 github.com: https://github.com/taskcluster/taskcluster/pull/8718 github.com: https://github.com/taskcluster/taskcluster/commit/a1b0154b8235937657c2ded127f193b564e2334b bugzilla.mozilla.org: https://bugzilla.mozilla.org/show_bug.cgi?id=2045091 github.com: https://github.com/taskcluster/taskcluster/releases/tag/v100.3.0