What is CVE-2026-47690?
CVE-2026-47690 is a vulnerability in the MeltanoHub repository that allows exfiltration of a write-enabled `GITHUB_TOKEN` via the `pull_request_target` trigger. This could allow an attacker to push code to the repository. Users of MeltanoHub should immediately update to a version containing the security patch (after commit `923820d`).
Azərbaycanca: CVE-2026-47690, MeltanoHub repozitoriyasında `pull_request_target` trigger'ı vasitəsilə yazma icazəli `GITHUB_TOKEN` məlumatının sızdırılmasına imkan verən boşluqdur. Bu zəiflikdən istifadə edərək təcavüzkar repoya kod əlavə edə bilər. MeltanoHub istifadəçiləri dərhal təhlükəsizlik yaması olan commit-ə (`923820d` sonrası) yenilənməlidir.
FAQ2
Through which mechanism is the CVE-2026-47690 vulnerability exploited in the MeltanoHub repository?
This vulnerability allows exfiltration of a write-enabled `GITHUB_TOKEN` via the `pull_request_target` trigger.
Which commit should MeltanoHub users update to in order to protect against CVE-2026-47690?
Users should immediately update to a version containing the security patch after commit `923820d`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.