


Perceptive Security
SOC/SIEM Consultancy

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-co…
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 19:03:21
Source:
nvd.nist.gov
Supply Chain & Dependencies, Cloud & Virtualization
CVE-2026-45131 affects CloudPirates Open Source Helm Charts collection. A vulnerability in the GitHub Actions workflow (pull-request.yaml) allows execution of attacker-controlled code from fork pull requests in a privileged context. This exposes repository secrets including Docker Hub credentials and tokens without requiring maintainer approval. The issue occurs prior to commit fcf9302 and has been patched via the same commit. The vulnerability represents a supply chain security risk through compromised CI/CD workflows.
Technical details
Mitigation steps:
Affected products:
CloudPirates Helm Charts
GitHub Actions
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45131
https://github.com/CloudPirates-io/helm-charts/commit/fcf930211604652aec15085895b6457bc8b73b54
https://github.com/CloudPirates-io/helm-charts/security/advisories/GHSA-c47r-c7gw-cvph
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
