CVE-2026-45132: Cloudpirates-Io Helm-Charts
Critical severity, CVSS 10.0. EPSS: 0.4% chance of exploitation in the next 30 days.
CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices. This issue has been patched via commit fcf9302.
Affected products
- Cloudpirates-Io Helm-Charts: before fcf930211604652aec15085895b6457bc8b73b54 (fixed in fcf930211604652aec15085895b6457bc8b73b54)
Published 2026-06-01. Last modified 2026-07-22.