Vulnerability Bulletins |
CVE-2026-45131 |
|
| Affected software | GITHUB |
| CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged context, exposing repository secrets including Docker Hub credentials and tokens without requiring maintainer approval. This issue has been patched via commit fcf9302. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-45131 | |






