Exfiltration Vulnerability in MeltanoHub by Meltano
CVE-2026-47690
7.5HIGH
What is CVE-2026-47690?
MeltanoHub, the source code repository for Meltano plugins, was found to be vulnerable to the exfiltration of the GITHUB_TOKEN that possesses write permissions to the repository. The flaw stemmed from the use of pull_request_target within the workflow, which executes in the context of the base repository, thus gaining access to sensitive secrets. This issue has been rectified as of commit 923820de8f64d753951fbbd54f7282a3d5f75173, but no known workarounds exist for impacted versions.
Affected Version(s)
hub < 923820de8f64d753951fbbd54f7282a3d5f75173
