CVE-2026-45132
CloudPirates Open Source Helm Charts had a flaw in its GitHub Actions workflow that exposed sensitive credentials to fork-controlled code. The issue was fixed in commit fcf9302. Users should update to the patched version to prevent credential leakage.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of CloudPirates Open Source Helm Charts who have not applied the patch commit fcf9302.
Real-world impact
An attacker could obtain personal access tokens and SSH signing keys, allowing them to impersonate the project or deploy malicious code.
Why this severity
The CVSS score of 10 reflects that the vulnerability can be exploited remotely with no authentication, exposing confidential and integrity-sensitive data, and the scope change indicates that the flaw can affect other components.
What to do about it
- 01Update the CloudPirates Open Source Helm Charts repository to a version that includes commit fcf9302 or later.
- 02Verify that the generate-schema.yaml workflow no longer exposes credentials.
NVD-referenced vendor advisory
Timeline
- Jun 1, 2026 · Jun 1, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.