top of page
perceptive_background_267k.jpg

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-co…

Published:

31 May 2026 at 22:00:00

Alert date:

1 June 2026 at 18:04:01

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Cloud & Virtualization

CloudPirates Open Source Helm Charts collection contains a vulnerability in GitHub Actions workflow (pull-request.yaml) that executes attacker-controlled code from fork pull requests in privileged context. The vulnerability exposes repository secrets including Docker Hub credentials and tokens without requiring maintainer approval. The issue allows attackers to access sensitive credentials through malicious pull requests. This represents a supply chain security risk affecting CI/CD pipelines. The vulnerability has been patched via commit fcf9302.

Technical details

Mitigation steps:

Affected products:

CloudPirates Helm Charts
GitHub Actions

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page