CVE-2026-55094
Received Received - Intake

Unauthenticated RCE in Taskcluster via GraphQL Filter

Vulnerability report for CVE-2026-55094, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mozilla taskcluster 100.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-250 The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CWE-95 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55094 is an unauthenticated remote code execution (RCE) vulnerability in Taskcluster, a task execution framework used by Mozilla. The issue occurs in deployments prior to version 100.3.0 where the GraphQL endpoint exposes a filter argument processed by the sift library. Attackers can send malicious filter inputs that compile into executable JavaScript, leading to arbitrary code execution in the web-server's Node.js process.

Detection Guidance

To detect this vulnerability, check if your Taskcluster deployment is running a version prior to 100.3.0. Verify if the GraphQL endpoint exposes a filter argument that uses the sift library for input processing. Inspect web-server logs for suspicious filter arguments containing $where or JavaScript code snippets.

Impact Analysis

This vulnerability allows attackers to execute arbitrary code on the affected Taskcluster server. If exploited, it could lead to full system compromise, data theft, or disruption of services. Systems with anonymous roles exposing the GraphQL endpoint or improperly configured authentication are at higher risk.

Mitigation Strategies

Upgrade Taskcluster to version 100.3.0 or later immediately. As a temporary workaround, set CSP_ENABLED in the web-server environment to disable the vulnerable code path. Rotate all web-server secrets after mitigation due to potential exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55094. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart