PatchSiren

meltano CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH meltano CVE published 2026-07-21

CVE-2026-47690

MeltanoHub, the source code for hub.meltano.com, had a vulnerability in versions prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173. The issue allowed for exfiltration of `GITHUB_TOKEN` with write permissions to the repository due to a vulnerable workflow using pull_request_target. This workflow runs in the context of the base repository with access to secrets. The fix was introduced in commit 92382 [truncated]