Code Injection Vulnerability in Meshtastic Open Source Networking Solution
CVE-2025-53637
What is CVE-2025-53637?
The Meshtastic networking solution is susceptible to a code injection vulnerability due to insecure handling of user-controlled input in its GitHub Action workflow. The problem arises when the main_matrix.yml file is triggered by the pull_request_target event, allowing attackers to exploit extensive permissions if they fork the repository. Unauthorized code can potentially be injected into the repository during this process. This vulnerability has been addressed in version 2.6.6, underscoring the importance of updating to the latest release.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
firmware >= 2.5.3, < 2.6.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
