Exfiltration Vulnerability in MeltanoHub by Meltano
CVE-2026-47690

7.5HIGH

Key Information:

Vendor

Meltano

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-47690?

MeltanoHub, the source code repository for Meltano plugins, was found to be vulnerable to the exfiltration of the GITHUB_TOKEN that possesses write permissions to the repository. The flaw stemmed from the use of pull_request_target within the workflow, which executes in the context of the base repository, thus gaining access to sensitive secrets. This issue has been rectified as of commit 923820de8f64d753951fbbd54f7282a3d5f75173, but no known workarounds exist for impacted versions.

Affected Version(s)

hub < 923820de8f64d753951fbbd54f7282a3d5f75173

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.