Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0. | |
| Title | Taskcluster: Unauthenticated remote code execution in `web-server` via GraphQL `filter` argument (sift `$where`) | |
| Weaknesses | CWE-20 CWE-250 CWE-306 CWE-94 CWE-95 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-30T19:12:22.456Z
Reserved: 2026-06-16T14:41:54.578Z
Link: CVE-2026-55094
No data.
Status : Received
Published: 2026-09-30T18:18:37.387
Modified: 2026-09-30T18:18:37.387
Link: CVE-2026-55094
No data.
OpenCVE Enrichment
No data.