PatchSiren

meshtastic CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL meshtastic CVE published 2026-07-20

CVE-2026-44359

A critical vulnerability was discovered in Meshtastic, an open-source mesh networking solution. The issue, tracked as CVE-2026-44359, exists in the main_matrix.yml workflow, which is triggered by pull_request_target. Multiple jobs in the workflow check out an attacker's fork code and execute it with access to repository secrets and elevated GITHUB_TOKEN permissions, without an approval gate. This allows a [truncated]

HIGH meshtastic CVE published 2026-07-20

CVE-2026-42566

A vulnerability in Meshtastic open source mesh networking solution prior to version 2.7.23.b246bcd can cause devices to become unusable over BLE when managed through the iOS app due to a malformed character encoding in a node's User.long_name. This issue arises from buffer truncation leading to a malformed name that can propagate through the mesh, causing BLE sync to enter a fail/retry loop and resulting [truncated]