Code Injection Risk in Network UPS Tools by GitHub Actions Misconfiguration
CVE-2026-54160
8.2HIGH
What is CVE-2026-54160?
A potential code injection vulnerability exists in Network UPS Tools due to the improper handling of GitHub Actions scripts. Specifically, a misconfiguration allowed higher privilege code to run alongside untrusted inputs. This flaw enabled attackers to exploit a malicious pull request from a fork, which could lead to the unauthorized extraction of the GITHUB_TOKEN. This could result in unauthorized manipulations of Git repository contents, such as altering commit statuses, checks, or comments within pull requests, thereby compromising the integrity of the codebase and its associated actions.
Affected Version(s)
nut < 658b24ef8410648ceca6d5a59e8690efbc8c36bc
