CVE-2026-54160: Network UPS Tools: A PWN Request in make-dist workflow can execute PR-controlled code with write-scoped GITHUB_TOKEN

Published Sep 28, 2026
·
Updated

Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitHub Checks statuses and PR comments about it was mis-structured in terms of mixing code running with higher privileges (single-use token generated with write permissions) and untrusted inputs (PR source branch). A malicious PR run from a fork could extract the GITHUBTOKEN value. It could potentially be abused while it was valid (while the GHA job ran) to manipulate Git repository contents, commit checks/statuses, or issue/PR comments, according to permissions it was issued with. This issue has been patched via commits 658b24e and 1aa31d1.

Affected Software

1 affected component
Network UPS Tools Network UPS Tools

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Network UPS Tools to a version that resolves this vulnerability.

    Patch 658b24e and 1aa31d1

Event History

Sep 28, 2026
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who could exploit this workflow flaw?

An attacker would need to submit a malicious pull request from a fork and have its workflow run. No repository credentials are required because the exposed token was available to the GitHub Actions job.

2

What could an attacker do with the exposed token?

During the job's lifetime, the attacker could potentially use the write-scoped GITHUB_TOKEN to manipulate repository contents, commit checks or statuses, and issue or pull-request comments, limited by the permissions issued to that token.

3

How can maintainers determine whether they are affected?

Review the repository's GitHub Actions workflow used to prepare NUT tarballs and update GitHub Checks statuses or PR comments. The issue affects workflow code from before commits 658b24e and 1aa31d1.

4

What should be done if the workflow cannot be updated immediately?

Do not run the affected workflow for pull requests from forks, since fork-controlled PR code is the untrusted input that can extract the token. The described remediation is to apply commits 658b24e and 1aa31d1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203