CVE-2026-54160
Received Received - Intake

GitHub Actions Token Exposure in Network UPS Tools

Vulnerability report for CVE-2026-54160, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitHub Checks statuses and PR comments about it was mis-structured in terms of mixing code running with higher privileges (single-use token generated with write permissions) and untrusted inputs (PR source branch). A malicious PR run from a fork could extract the GITHUB_TOKEN value. It could potentially be abused while it was valid (while the GHA job ran) to manipulate Git repository contents, commit checks/statuses, or issue/PR comments, according to permissions it was issued with. This issue has been patched via commits 658b24e and 1aa31d1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
network_ups_tools nut to 658b24e|end_excluding=1aa31d1 (exc)
networkupstools nut to 2.8.5 (exc)
networkupstools nut From 2.8.5 (inc) to 2.8.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-54160 is a vulnerability in Network UPS Tools (NUT) GitHub Actions workflow where a misconfigured script mixed high-privilege operations using a write-scoped GITHUB_TOKEN with untrusted inputs from pull requests originating from forks. This allowed malicious PR authors to extract and abuse the token to manipulate repository contents, checks, statuses, or PR comments while the token was valid.

Detection Guidance

This vulnerability is specific to the GitHub Actions workflow in Network UPS Tools. To detect it, check if your repository uses the vulnerable `.github/workflows/01-make-dist*.yml` workflow files. Inspect the workflow for mixing high-privilege operations with untrusted inputs from forked PRs. Compare the workflow against the patched versions in commits 658b24e and 1aa31d1.

Impact Analysis

If you use NUT's GitHub Actions workflows with the flawed setup, a malicious actor could gain write access to your repository, modify files, alter checks or statuses, or manipulate PR comments. This could lead to unauthorized changes or misinformation in your project. The impact is limited to repositories using the vulnerable workflow scripts.

Compliance Impact

The vulnerability could potentially lead to unauthorized modifications of repository contents, checks, or comments due to the misuse of a high-privilege GITHUB_TOKEN. This may impact compliance with standards requiring data integrity and access controls, such as GDPR (data integrity) or HIPAA (access controls), if exploited.

Mitigation Strategies

Update the GitHub Actions workflow files `.github/workflows/01-make-dist*.yml` to the patched versions from commits 658b24e and 1aa31d1. Split the workflow into separate processes: one for metadata writes with reduced permissions and another for build and artifact uploads. Enable GitHub’s vulnerability reporting and Dependabot for additional security.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54160. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart