CVE-2026-45131

CRITICAL

CloudPirates Helm Charts - GitHub Actions Secret Exfiltration

Title source: manual
STIX 2.1

Description

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged context, exposing repository secrets including Docker Hub credentials and tokens without requiring maintainer approval. This issue has been patched via commit fcf9302.

Scores

CVSS v3 10.0
EPSS 0.0027
EPSS Percentile 19.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Details

CWE
CWE-94
Status published
Products (1)
CloudPirates-io/helm-charts < fcf930211604652aec15085895b6457bc8b73b54
Published Jun 01, 2026
Tracked Since Jun 01, 2026