Security: meshtastic/firmware
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Malformed encoding in User.long_name broadcast over LoRa causes client decode failureGHSA-7ph5-2mjv-69h8 published
Jul 9, 2026 by thebenternHigh -
Arbitrary Code Execution via pull_request_target Fork Checkout in CI WorkflowGHSA-mjx5-98jq-q736 published
Apr 20, 2026 by thebenternCritical -
Crafting of specific NodeInfo packets overwrite any publicKey saved in the NodeDBGHSA-95pq-gj5v-4fg2 published
Aug 16, 2025 by thebenternCritical -
Repeated Public/Private KeypairsGHSA-gq7v-jr8c-mfr7 published
Jun 18, 2025 by jp-bennettCritical -
Command Injection in GitHub ActionGHSA-6mwm-v2vv-pp96 published
Jul 10, 2025 by garthvhModerate -
Forged DMs with no PKC show up as encryptedGHSA-377p-prwp-4hwf published
Dec 29, 2025 by jp-bennettModerate -
An attacker can spoof licensed amateur flag for a nodeGHSA-45vg-3f35-7ch2 published
Jan 27, 2026 by thebenternHigh -
[Low Priority] - On linux-native hosts, the self-signed/generated TLS key material is world-readable.GHSA-h79j-c836-5j74 published
Aug 1, 2025 by garthvhLow -
Incorrect handling of malformed packets leads to controlled buffer overflowGHSA-33hw-xhfh-944r published
Apr 11, 2025 by thebenternCritical -
Unimplemented routing module reply causes crashGHSA-4q84-546j-3mf5 published
Jul 10, 2025 by garthvhModerate