


Perceptive Security
SOC/SIEM Consultancy

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive…
Published:
31 mei 2026 om 22:00:00
Alert date:
1 juni 2026 om 19:03:21
Source:
nvd.nist.gov
Supply Chain & Dependencies, Cloud & Virtualization
CloudPirates Open Source Helm Charts contained a vulnerability in their GitHub Actions workflow (generate-schema.yaml) that exposed sensitive credentials including Personal Access Token and SSH signing key to fork-controlled code. The vulnerability was caused by unsafe checkout and credential handling practices in the CI/CD pipeline. This security flaw allowed potential unauthorized access to sensitive authentication materials through malicious forks. The issue was addressed and patched via commit fcf9302. The vulnerability represents a supply chain security risk affecting the Helm Charts collection.
Technical details
Mitigation steps:
Affected products:
CloudPirates Helm Charts
GitHub Actions
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45132
https://github.com/CloudPirates-io/helm-charts/commit/fcf930211604652aec15085895b6457bc8b73b54
https://github.com/CloudPirates-io/helm-charts/security/advisories/GHSA-r874-j8fr-x2pj
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
