No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Meltano
Meltano hub |
|
| Vendors & Products |
Meltano
Meltano hub |
Wed, 22 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration of `GITHUB_TOKEN` with write permissions to the repository. The vulnerable workflow used pull_request_target, which runs in the context of the base repository with access to secrets. Commit 923820de8f64d753951fbbd54f7282a3d5f75173 fixes the issue. No known workarounds are available. | |
| Title | MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workflow | |
| Weaknesses | CWE-1336 CWE-77 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-22T14:59:37.761Z
Reserved: 2026-05-19T21:18:20.403Z
Link: CVE-2026-47690
Updated: 2026-07-22T14:59:32.031Z
Status : Awaiting Analysis
Published: 2026-07-21T21:16:51.067
Modified: 2026-07-23T16:15:11.587
Link: CVE-2026-47690
No data.
OpenCVE Enrichment
Updated: 2026-07-30T16:30:05Z