CVE-2026-45131: CWE-94: Improper Control of Generation of Code ('Code Injection') in CloudPirates-io helm-charts
CVE-2026-45131 is a critical code injection vulnerability in CloudPirates-io's open source Helm charts. Before a specific commit (fcf9302), a GitHub Actions workflow executed attacker-controlled code from forked pull requests with privileged access, exposing sensitive repository secrets such as Docker Hub credentials and tokens without requiring maintainer approval. This vulnerability has been patched in commit fcf9302. The CVSS score is 10.0, indicating a critical severity with network attack vector, no privileges or user interaction required, and complete confidentiality and integrity impact. No known exploits in the wild have been reported.
AI Analysis
Technical Summary
CloudPirates-io's Helm charts contained a vulnerability (CVE-2026-45131) where a GitHub Actions workflow (pull-request.yaml) ran code from fork pull requests in a privileged context. This allowed attackers to execute arbitrary code and access repository secrets including Docker Hub credentials and tokens without maintainer approval. The issue was fixed by commit fcf9302, which prevents execution of untrusted code in this context. The vulnerability is classified as CWE-94 (Improper Control of Generation of Code) and has a CVSS 3.1 base score of 10.0, reflecting its critical impact and ease of exploitation.
Potential Impact
An attacker can execute arbitrary code in the context of the GitHub Actions workflow without requiring maintainer approval, leading to exposure of sensitive repository secrets such as Docker Hub credentials and tokens. This compromises confidentiality and integrity of the repository environment. The vulnerability does not affect availability. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
This vulnerability has been patched by commit fcf9302 in the CloudPirates-io helm-charts repository. Users should update to the fixed version at or beyond this commit to remediate the issue. Since this is not a cloud service, remediation requires applying the patch to the affected codebase. Patch status is confirmed by the vendor commit reference. No additional mitigation steps are indicated.
CVE-2026-45131: CWE-94: Improper Control of Generation of Code ('Code Injection') in CloudPirates-io helm-charts
Description
CVE-2026-45131 is a critical code injection vulnerability in CloudPirates-io's open source Helm charts. Before a specific commit (fcf9302), a GitHub Actions workflow executed attacker-controlled code from forked pull requests with privileged access, exposing sensitive repository secrets such as Docker Hub credentials and tokens without requiring maintainer approval. This vulnerability has been patched in commit fcf9302. The CVSS score is 10.0, indicating a critical severity with network attack vector, no privileges or user interaction required, and complete confidentiality and integrity impact. No known exploits in the wild have been reported.
CVSS v3.1
Score 10.0critical
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CloudPirates-io's Helm charts contained a vulnerability (CVE-2026-45131) where a GitHub Actions workflow (pull-request.yaml) ran code from fork pull requests in a privileged context. This allowed attackers to execute arbitrary code and access repository secrets including Docker Hub credentials and tokens without maintainer approval. The issue was fixed by commit fcf9302, which prevents execution of untrusted code in this context. The vulnerability is classified as CWE-94 (Improper Control of Generation of Code) and has a CVSS 3.1 base score of 10.0, reflecting its critical impact and ease of exploitation.
Potential Impact
An attacker can execute arbitrary code in the context of the GitHub Actions workflow without requiring maintainer approval, leading to exposure of sensitive repository secrets such as Docker Hub credentials and tokens. This compromises confidentiality and integrity of the repository environment. The vulnerability does not affect availability. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
This vulnerability has been patched by commit fcf9302 in the CloudPirates-io helm-charts repository. Users should update to the fixed version at or beyond this commit to remediate the issue. Since this is not a cloud service, remediation requires applying the patch to the affected codebase. Patch status is confirmed by the vendor commit reference. No additional mitigation steps are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-08T20:08:17.209Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a1dbba3e29bf47b501c57a3
Added to database: 06/01/2026, 17:04:35 UTC
Last enriched: 06/08/2026, 21:07:20 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 68
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.