CVE-2026-44359: Meshtastic CI/CD Workflow Exposes Repository Secrets (CVSS 10.0)
ID: 749d1823-faad-585d-8892-05302e0ea34b
STIX ID: report--749d1823-faad-585d-8892-05302e0ea34b
Feed Name: CosmicBytez Labs
Threat Score
**Meshtastic CVE-2026-44359 (CVSS 10.0):** A misconfigured GitHub Actions workflow using the pull_request_target trigger combined with checking out attacker fork code allows untrusted code to execute in the base repository context, exposing repository secrets, write tokens, and enabling supply-chain compromise; the issue is fixed in Meshtastic firmware version 2.7.21.1370b23 and the report includes remediation, detection guidance, and recommended secret rotation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
