CVE-2026-54168: Tektoncd Pipelines-As-Code
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the repository that triggered the event when the App is installed across multiple repositories. A user with push access to one repository can submit a PipelineRun containing a pipelinesascode.tekton.dev/task remote task annotation that targets a private repository in the same installation. When ScopeTokenToListOfRepos returns no explicit scope, the missing triggering repository ID leaves the token able to access the entire installation. Pipelines-as-Code resolves and inlines the remote private task with that token, disclosing the repository's Tekton definitions. The demonstrated impact is read-only and does not provide write access. This issue is fixed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0.
Affected products
- Tektoncd Pipelines-As-Code: before 0.37.8 (fixed in 0.37.8); from 0.38.0, before 0.39.6 (fixed in 0.39.6); from 0.40.0, before 0.42.1 (fixed in 0.42.1); from 0.43.0, before 0.48.0 (fixed in 0.48.0)
Published 2026-09-15. Last modified 2026-09-30.