CVE Explorer
CVE-2026-45132
CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices. This issue has been patched via commit fcf9302.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"helm-charts","vendor":"CloudPirates-io","versions":[{"status":"affected","version":"< fcf930211604652aec15085895b6457bc8b73b54"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d84df854738acb64fc2d35df8834e94e63f75d91f922a67e57e95f62c104256f · sha256:f9f40b70b30f25cc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d84df854738acb64fc2d35df8834e94e63f75d91f922a67e57e95f62c104256f · sha256:f9f40b70b30f25cc… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-94","description":"CWE-94: Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d84df854738acb64fc2d35df8834e94e63f75d91f922a67e57e95f62c104256f · sha256:f9f40b70b30f25cc… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/CloudPirates-io/helm-charts/commit/fcf930211604652aec15085895b6457bc8b73b54","tags":["x_refsource_MISC"],"url":"https://github.com/CloudPirates-io/helm-charts/commit/fcf930211604652aec15085895b6457bc8b73b54"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d84df854738acb64fc2d35df8834e94e63f75d91f922a67e57e95f62c104256f · sha256:f9f40b70b30f25cc… · /containers/cna/references/1
{"name":"https://github.com/CloudPirates-io/helm-charts/security/advisories/GHSA-r874-j8fr-x2pj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/CloudPirates-io/helm-charts/security/advisories/GHSA-r874-j8fr-x2pj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d84df854738acb64fc2d35df8834e94e63f75d91f922a67e57e95f62c104256f · sha256:f9f40b70b30f25cc… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.