CVE-2026-44359
Meshtastic, an open‑source mesh networking platform, had a critical flaw in its GitHub Actions workflow that let attackers run arbitrary code during CI. The bug existed before version 2.7.21.1370b23 and could let a malicious pull request execute with repository secrets. The issue was fixed in that release.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Meshtastic users running any version older than 2.7.21.1370b23, especially those who allow external pull requests to trigger the main_matrix.yml workflow.
Real-world impact
An attacker could inject code into the CI pipeline, gaining access to repository secrets, compromising self‑hosted runners, or taking over the repository.
Why this severity
The CVSS score of 10 reflects that the vulnerability is exploitable over the network, requires no special privileges, has no user interaction, and changes the scope of the affected system, giving the attacker full confidentiality and integrity compromise.
What to do about it
- 01Upgrade Meshtastic to version 2.7.21.1370b23 or later.
NVD-referenced vendor advisory
Timeline
- Jul 20, 2026 · 13d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 24, 2026 · 9d agoAdvisory updatedThe NVD record was last revised.