Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-54160— Network UPS Tools: A PWN Request in make-dist workflow can execute PR-controlled code with write-scoped GITHUB_TOKEN

Quick assessment

Affected
networkupstools nut
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Network UPS Tools(NUT)是一套用于监控和管理 UPS(不间断电源)、PDU(电源分配单元)以及 SCD(系统关闭装置)等硬件设备的程序集合。在提交 658b24e 和 1aa31d1 之前,用于准备 NUT 软件包(tarballs)并更新 GitHub Checks 状态以及相关 PR(拉取请求)评论的 GitHub Actions 脚本结构存在缺陷:该脚本将具有较高权限的代码执行(使用了具有写权限的单次使用令牌)与不可信输入(PR 的源分支)混合在一起。来自 fork 仓库的恶意 PR 可能

CVSS 8.2 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
networkupstools nut < 658b24ef8410648ceca6d5a59e8690efbc8c36bc affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54160

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Network UPS Tools: A PWN Request in make-dist workflow can execute PR-controlled code with write-scoped GITHUB_TOKEN
Source: CVE Program / CVE List V5
Vulnerability Description
Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitHub Checks statuses and PR comments about it was mis-structured in terms of mixing code running with higher privileges (single-use token generated with write permissions) and untrusted inputs (PR source branch). A malicious PR run from a fork could extract the GITHUB_TOKEN value. It could potentially be abused while it was valid (while the GHA job ran) to manipulate Git repository contents, commit checks/statuses, or issue/PR comments, according to permissions it was issued with. This issue has been patched via commits 658b24e and 1aa31d1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
从非可信控制范围包含功能例程
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
networkupstools nut < 658b24ef8410648ceca6d5a59e8690efbc8c36bc -

II. Public POCs for CVE-2026-54160

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54160

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-54160 (1)

Vendor Advisories for CVE-2026-54160 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54160

No comments yet


Leave a comment