CVE-2026-55094 Details
Description
Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0.
A remote code execution vulnerability has been identified in Taskcluster, specifically in versions prior to 100.3.0. The issue arises in deployments where the anonymous role allows access to the GraphQL endpoint, and the filter arguments are parsed using the sift library. This vulnerability is particularly critical as it is unauthenticated and can be exploited by anyone with access to the affected GraphQL queries.
Users can upgrade to Taskcluster version 100.3.0 or later, where this vulnerability has been patched. For those unable to upgrade immediately, it is recommended to set the 'CSP_ENABLED' environment variable in the web-server to disable the vulnerable 'sift' filter parsing. After upgrading or applying this workaround, all 'web-server' secrets should be rotated, as they were exposed to the process.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=2045091 | [email protected] | Issue TrackingPermission RequiredVendor |
| https://github.com/taskcluster/taskcluster/commit/a1b0154b8235937657c2ded127f193b564e2334b | [email protected] | Source CodeVendor |
| https://github.com/taskcluster/taskcluster/issues/8716 | [email protected] | Issue TrackingVendor |
| https://github.com/taskcluster/taskcluster/pull/8718 | [email protected] | Issue TrackingVendor |
| https://github.com/taskcluster/taskcluster/releases/tag/v100.3.0 | [email protected] | Release NotesVendor |
| https://github.com/taskcluster/taskcluster/security/advisories/GHSA-ccv5-c45x-2q38 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-250 | Execution with Unnecessary Privileges | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
| CWE-95 | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Taskcluster | < 100.3.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion