Skip to main content
Mallory
Critical

Privileged GitHub Actions fork PR secret exposure in CloudPirates Open Source Helm Charts

IdentifiersCVE-2026-45131CWE-94· Improper Control of Generation of…

CVE-2026-45131 affects CloudPirates Open Source Helm Charts. Prior to commit fcf930211604652aec15085895b6457bc8b73b54, the repository's GitHub Actions workflow file pull-request.yaml executed attacker-controlled code originating from forked pull requests in a privileged workflow context. Because the workflow ran with access to repository secrets and did not require maintainer approval before executing the untrusted code, an external attacker could submit a crafted fork PR and cause the workflow to expose sensitive secrets, including Docker Hub credentials and tokens. The issue was patched in commit fcf930211604652aec15085895b6457bc8b73b54.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated external attacker controlling a forked pull request to access repository secrets available to the privileged GitHub Actions workflow. Reported exposed material includes Docker Hub credentials and tokens. Compromise of these secrets can enable unauthorized access to associated services, abuse of CI/CD trust relationships, tampering with published artifacts or container images, and further supply-chain compromise. The provided CVSS vector indicates high confidentiality and integrity impact, with no direct availability impact stated.

Mitigation

If you can’t patch tonight, do this now.

Until the patch is applied, disable or restrict the vulnerable pull-request.yaml workflow for fork-based pull requests, prevent privileged workflow execution on untrusted PRs, and ensure secrets are not exposed to workflows triggered by forks. Require maintainer approval before running workflows from external contributors where possible. As a precaution, remove unnecessary secrets from CI, scope tokens to least privilege, and monitor for misuse of Docker Hub credentials and other repository tokens.

Remediation

Patch, then assume compromise.

Update to the patched revision that includes commit fcf930211604652aec15085895b6457bc8b73b54 (referenced as commit fcf9302). Review and modify the affected GitHub Actions workflow pull-request.yaml so that untrusted code from forked pull requests is not executed in a privileged context and does not have access to repository secrets. Rotate any potentially exposed secrets, including Docker Hub credentials and tokens, and audit downstream systems and published artifacts for unauthorized use.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity5

Community discussion across Reddit, Mastodon, and other social sources.