---
id: CVE-2026-55094
title: >-
  Taskcluster is the task execution framework that supports Mozilla's continuous
  integration and release processes
summary: >-
  Taskcluster is the task execution framework that supports Mozilla's continuous
  integration and release processes. Prior to version 100.3.0, Taskcluster is
  vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous
  rol…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-20
  - CWE-94
  - CWE-95
  - CWE-250
  - CWE-306
vendor: taskcluster
product: taskcluster
affected:
  - taskcluster < 100.3.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T20:17:32.590'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55094'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=2045091'
    label: security-advisories@github.com
  - url: >-
      https://github.com/taskcluster/taskcluster/commit/a1b0154b8235937657c2ded127f193b564e2334b
    label: security-advisories@github.com
  - url: 'https://github.com/taskcluster/taskcluster/issues/8716'
    label: security-advisories@github.com
  - url: 'https://github.com/taskcluster/taskcluster/pull/8718'
    label: security-advisories@github.com
  - url: 'https://github.com/taskcluster/taskcluster/releases/tag/v100.3.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/taskcluster/taskcluster/security/advisories/GHSA-ccv5-c45x-2q38
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-30T19:12:04.595464Z'
cvssSource: cna
ingestedAt: '2026-09-30T18:17:24.547Z'
---

## Overview

Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
