Unauthenticated Remote Code Execution in Taskcluster by Mozilla
CVE-2026-55094

8.7HIGH

Key Information:

Vendor
CVE Published:
30 September 2026

What is CVE-2026-55094?

Taskcluster, the task execution framework supporting Mozilla's CI and release processes, is susceptible to unauthenticated remote code execution when deployed with an anonymous role that reveals its GraphQL endpoint. The vulnerability arises from the parsing of filter arguments using the sift library, allowing potential attackers to exploit this weak configuration. This critical vulnerability has been addressed in version 100.3.0, which is now available, urging users to upgrade to secure their deployments.

Affected Version(s)

taskcluster < 100.3.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.