天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-54160 Network UPS Tools 权限提升漏洞

影响恶意 PR 可窃取 GITHUB_TOKEN 并篡改仓库内容与状态

AI 研判

Network UPS Tools(NUT)的 GitHub Actions 脚本在准备发布 tarball、更新检查状态和 PR 评论时,将高权限代码(具备写权限的一次性令牌)与不可信输入(PR 来源分支)混在一起执行。攻击者可从 fork 发起恶意 PR,从而提取 GITHUB_TOKEN。该问题已通过提交 658b24e 和 1aa31d1 修复。

影响范围

Network UPS Tools

Network UPS Tools 在提交 658b24e 和 1aa31d1 之前的版本;具体受影响版本号暂无公开信息。

漏洞详情

漏洞属于 CI/CD 工作流中的权限混淆/不可信输入注入问题。GitHub Actions 脚本把拥有写权限的 GITHUB_TOKEN 暴露在会处理 fork PR 代码的上下文中,导致攻击者可通过构造恶意 PR 读取该令牌。令牌在作业运行期间有效,可被用于操纵 Git 仓库内容、提交检查/状态或 issue/PR 评论。

利用条件与风险

利用前提是攻击者能向目标仓库提交来自 fork 的 PR,且工作流会运行该 PR 代码;实战中可造成仓库内容与 CI 状态被篡改,风险较高。

修复建议

官方已通过提交 658b24e 和 1aa31d1 修复,建议升级到包含这两个提交的版本;临时缓解可限制工作流对 fork PR 的触发权限、最小化 GITHUB_TOKEN 权限并避免在不可信上下文中使用写权限令牌。

原始情报

Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitHub Checks statuses and PR comments about it was mis-structured in terms of mixing code running with higher privileges (single-use token generated with write permissions) and untrusted inputs (PR source branch). A malicious PR run from a fork could extract the GITHUB_TOKEN value. It could potentially be abused while it was valid (while the GHA job ran) to manipulate Git repository contents, commit checks/statuses, or issue/PR comments, according to permissions it was issued with. This issue has been patched via commits 658b24e and 1aa31d1.