Code Injection Risk in Network UPS Tools by GitHub Actions Misconfiguration
CVE-2026-54160

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-54160?

A potential code injection vulnerability exists in Network UPS Tools due to the improper handling of GitHub Actions scripts. Specifically, a misconfiguration allowed higher privilege code to run alongside untrusted inputs. This flaw enabled attackers to exploit a malicious pull request from a fork, which could lead to the unauthorized extraction of the GITHUB_TOKEN. This could result in unauthorized manipulations of Git repository contents, such as altering commit statuses, checks, or comments within pull requests, thereby compromising the integrity of the codebase and its associated actions.

Affected Version(s)

nut < 658b24ef8410648ceca6d5a59e8690efbc8c36bc

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.