A vulnerability marked as problematic has been reported in Meshtastic 2.5.21/2.7.15. This affects the function
pull_request_target of the file main_matrix.yml of the component Workflow. The manipulation of the argument author_association leads to command injection.
This vulnerability is documented as CVE-2026-44359. The attack can be initiated remotely. There is not any exploit available.