CVE-2026-45132

CRITICAL

CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential handling

Title source: cna
STIX 2.1

Description

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices. This issue has been patched via commit fcf9302.

Scores

CVSS v3 10.0
EPSS 0.0026
EPSS Percentile 17.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Details

CWE
CWE-94
Status published
Products (1)
CloudPirates-io/helm-charts < fcf930211604652aec15085895b6457bc8b73b54
Published Jun 01, 2026
Tracked Since Jun 01, 2026