Description
Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 30 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0. | |
| Title | Taskcluster: Unauthenticated remote code execution in `web-server` via GraphQL `filter` argument (sift `$where`) | |
| Weaknesses | CWE-20 CWE-250 CWE-306 CWE-94 CWE-95 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-30T17:22:52.135Z
Reserved: 2026-06-16T14:41:54.578Z
Link: CVE-2026-55094
No data.
Status : Received
Published: 2026-09-30T18:18:37.387
Modified: 2026-09-30T18:18:37.387
Link: CVE-2026-55094
No data.
OpenCVE Enrichment
No data.
Weaknesses