CVE-2026-45131 is a CI/CD pipeline vulnerability in CloudPirates Open Source Helm Charts affecting the GitHub Actions workflow pull-request.yaml prior to commit fcf9302. The workflow used an unsafe pattern in which attacker-controlled code from a forked pull request was executed in a privileged context associated with the target repository. Because this execution context had access to repository secrets, an unauthenticated attacker could submit a pull request from a fork and cause the workflow to run code under conditions that exposed sensitive credentials, including Docker Hub credentials and repository tokens, without requiring maintainer approval. The flaw is classified as CWE-94 due to improper control over execution of untrusted code within the automation pipeline.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This 100-file repository is an automated research snapshot of CloudPirates Helm charts, explicitly described in README.md as a disposable laboratory artifact for reproducing public GitHub Actions workflow vulnerabilities. It is not a conventional network exploit or malware repository. Its principal security-relevant artifact is .github/workflows/generate-schema.yaml: it is triggered by pull_request_target for changes beneath charts/**/values.yaml, checks out the attacker-controlled PR-head SHA, installs and invokes Helm tooling, and has contents: write permission while checkout uses the privileged CHANGELOG_PAT token. Processing attacker-controlled content in this privileged pull_request_target context can provide a path to runner command execution and subsequent credential/repository abuse. The related pull-request workflow also checks out PR code, but declares read-only contents permission. The repository is organized as a Helm-chart monorepo: charts/common provides shared Go-template helpers; charts/clusterpirate deploys a Kubernetes observability agent with cluster-wide read/list/watch RBAC and a CloudPirates registration endpoint; charts/etcd deploys a stateful etcd cluster; charts/ghost deploys Ghost and optional MariaDB; and charts/keycloak begins an IAM deployment. Chart directories contain Chart.yaml metadata, default values, JSON schemas, rendered Kubernetes Go templates, and Helm unit tests. GitHub Actions automate linting, integration testing, schema generation, changelog generation, signing/release activities, and issue management. The available source contains YAML, Helm/Go templates, JSON, and inline Bash/JavaScript, with no standalone exploit script or hard-coded malicious payload.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Критическая уязвимость в GitHub Actions workflow pull-request.yaml репозитория CloudPirates Open Source Helm Charts, где pull_request_target и небезопасный checkout PR-кода из форка приводили к выполнению кода атакующего в привилегированном контексте и раскрытию секретов репозитория.
A vulnerability in CloudPirates Open Source Helm Charts where a GitHub Actions workflow executed attacker-controlled code from forked pull requests in a privileged context, potentially exposing repository secrets such as Docker Hub credentials and tokens.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.