


Perceptive Security
SOC/SIEM Consultancy

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-co…
Published:
31 mei 2026 om 22:00:00
Alert date:
1 juni 2026 om 18:04:01
Source:
nvd.nist.gov
Supply Chain & Dependencies, Cloud & Virtualization
CloudPirates Open Source Helm Charts collection contains a vulnerability in GitHub Actions workflow (pull-request.yaml) that executes attacker-controlled code from fork pull requests in privileged context. The vulnerability exposes repository secrets including Docker Hub credentials and tokens without requiring maintainer approval. The issue allows attackers to access sensitive credentials through malicious pull requests. This represents a supply chain security risk affecting CI/CD pipelines. The vulnerability has been patched via commit fcf9302.
Technical details
Mitigation steps:
Affected products:
CloudPirates Helm Charts
GitHub Actions
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45131
https://github.com/CloudPirates-io/helm-charts/commit/fcf930211604652aec15085895b6457bc8b73b54
https://github.com/CloudPirates-io/helm-charts/security/advisories/GHSA-c47r-c7gw-cvph
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
