CVE-2026-45132 is a CI/CD workflow vulnerability in CloudPirates Open Source Helm Charts affecting the GitHub Actions workflow generate-schema.yaml prior to commit fcf9302. The flaw stems from unsafe checkout of attacker-controlled pull request code together with unsafe credential handling in a privileged workflow context, allowing fork-controlled code to access sensitive credentials during workflow execution. Reported exposed secrets included a GitHub Personal Access Token and an SSH commit-signing key. The vulnerable pattern is consistent with misuse of privileged pull request processing in GitHub Actions, where untrusted code from a fork can execute in a context that has access to repository secrets and elevated token permissions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a 100-file automated research artifact containing a snapshot of CloudPirates Helm charts at commit 9f5a7186b46070ceae3e80740ab64955b88fc65a. It is not conventional malware or a standalone exploit program; it is intended to reproduce a public GitHub Actions workflow vulnerability. The key risky files are .github/workflows/generate-schema.yaml and .github/workflows/pull-request.yaml. Both use pull_request_target and explicitly check out the fork/PR head, causing subsequently invoked tooling to process attacker-controlled repository content. The generate-schema workflow is the highest-risk path: it declares contents: write and pull-requests: write permissions, checks out the PR SHA using secrets.CHANGELOG_PAT, installs a Helm plugin, generates schemas, and may commit/push changes. The pull-request workflow similarly checks out untrusted PR content and runs Helm/chart-testing, Helm plugins, and integration tests; it is configured with read-only GitHub permissions but supplies Docker registry credentials to its integration-test job. The repository otherwise consists of Helm charts and templates for ClusterPirate, etcd, Ghost, Keycloak, and shared helpers, with YAML/Go-template manifests, JSON schemas, CI values, and GitHub Actions automation. The ClusterPirate chart is notable because it deploys an observability agent with cluster-wide read/list/watch permissions for workloads, nodes, metrics, and Kubernetes events, and configures the agent to register with api.cloudpirates.io. No CVE ID, hardcoded exploit payload, reverse shell, or destructive command was identified.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Критическая уязвимость в GitHub Actions workflow generate-schema.yaml репозитория CloudPirates Open Source Helm Charts, позволяющая коду из fork PR получить PAT и SSH signing key из-за небезопасного checkout в привилегированном контексте.
A vulnerability in CloudPirates Open Source Helm Charts where a GitHub Actions workflow exposed sensitive credentials to fork-controlled code because of unsafe checkout and credential handling practices.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.