CVE-2026-54160: Network UPS Tools: A PWN Request in make-dist workflow can execute PR-controlled code with write-scoped GITHUB_TOKEN
Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitHub Checks statuses and PR comments about it was mis-structured in terms of mixing code running with higher privileges (single-use token generated with write permissions) and untrusted inputs (PR source branch). A malicious PR run from a fork could extract the GITHUBTOKEN value. It could potentially be abused while it was valid (while the GHA job ran) to manipulate Git repository contents, commit checks/statuses, or issue/PR comments, according to permissions it was issued with. This issue has been patched via commits 658b24e and 1aa31d1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Network UPS Toolsto a version that resolves this vulnerability.Patch 658b24e and 1aa31d1
Event History
Frequently Asked Questions
Who could exploit this workflow flaw?
An attacker would need to submit a malicious pull request from a fork and have its workflow run. No repository credentials are required because the exposed token was available to the GitHub Actions job.
What could an attacker do with the exposed token?
During the job's lifetime, the attacker could potentially use the write-scoped GITHUB_TOKEN to manipulate repository contents, commit checks or statuses, and issue or pull-request comments, limited by the permissions issued to that token.
How can maintainers determine whether they are affected?
Review the repository's GitHub Actions workflow used to prepare NUT tarballs and update GitHub Checks statuses or PR comments. The issue affects workflow code from before commits 658b24e and 1aa31d1.
What should be done if the workflow cannot be updated immediately?
Do not run the affected workflow for pull requests from forks, since fork-controlled PR code is the untrusted input that can extract the token. The described remediation is to apply commits 658b24e and 1aa31d1.