๐Ÿ” CVE Alert

CVE-2026-55094

UNKNOWN 0.0

Taskcluster: Unauthenticated remote code execution in `web-server` via GraphQL `filter` argument (sift `$where`)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0.

CWE CWE-20 CWE-94 CWE-95 CWE-250 CWE-306
Vendor taskcluster
Product taskcluster
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for taskcluster taskcluster

Be the first to know when new unknown vulnerabilities affecting taskcluster taskcluster are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

taskcluster / taskcluster
< 100.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/taskcluster/taskcluster/security/advisories/GHSA-ccv5-c45x-2q38 github.com: https://github.com/taskcluster/taskcluster/issues/8716 github.com: https://github.com/taskcluster/taskcluster/pull/8718 github.com: https://github.com/taskcluster/taskcluster/commit/a1b0154b8235937657c2ded127f193b564e2334b bugzilla.mozilla.org: https://bugzilla.mozilla.org/show_bug.cgi?id=2045091 github.com: https://github.com/taskcluster/taskcluster/releases/tag/v100.3.0