CVE-2026-45132

CRITICAL

CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential handling

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-45132. PoCs published by ghapvharmo.

AI-analyzed exploit summary This repository contains Helm chart maintenance scripts and templates for RabbitMQ CRD updates, local chart testing, and dependency management. It does not contain exploit code or vulnerability details for CVE-2026-45132, only infrastructure-related scripts for chart management.

Description

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices. This issue has been patched via commit fcf9302.

Exploits (1)

nomisec STUB
by ghapvharmo · poc
https://github.com/ghapvharmo/gha-lab-a815a82f03-1

This repository contains Helm chart maintenance scripts and templates for RabbitMQ CRD updates, local chart testing, and dependency management. It does not contain exploit code or vulnerability details for CVE-2026-45132, only infrastructure-related scripts for chart management.

Classification
Stub 95%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: RabbitMQ Cluster Operator and Messaging Topology Operator (Helm charts)
No auth needed
Prerequisites: Helm, kubectl, kind, and yq installed · Access to GitHub repositories for CRD updates
mistral-large-3 · analyzed Jul 24, 2026 Full analysis →

Scores

CVSS v3 10.0
EPSS 0.0026
EPSS Percentile 17.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Details

CWE
CWE-94
Status published
Products (1)
CloudPirates-io/helm-charts < fcf930211604652aec15085895b6457bc8b73b54
Published Jun 01, 2026
Tracked Since Jun 01, 2026