CVE-2026-47690

Source
https://cve.org/CVERecord?id=CVE-2026-47690
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47690.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-47690
Aliases
  • GHSA-wrpf-f35c-j28w
Published
2026-07-21T20:46:26.449Z
Modified
2026-07-23T04:03:20.238044125Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workflow
Details

MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration of GITHUB_TOKEN with write permissions to the repository. The vulnerable workflow used pullrequesttarget, which runs in the context of the base repository with access to secrets. Commit 923820de8f64d753951fbbd54f7282a3d5f75173 fixes the issue. No known workarounds are available.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47690.json",
    "cna_assigner": "GitHub_M",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "923820de8f64d753951fbbd54f7282a3d5f75173"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-1336",
        "CWE-77"
    ]
}
References

Affected packages

Git / github.com/meltano/hub

Affected ranges

Type
GIT
Repo
https://github.com/meltano/hub
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

Other
old-hub

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47690.json"