Threat Advisory

Tekton Pipelines-as-Code Flaw Compromises Resources Using Excessively Trusted Deployment Retrieval Keys

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A Tekton Pipelines-as-Code vulnerability CVE-2026-54168 with a CVSS score of 6.5 allows unauthorized access to private repositories through remote task resolution when configured with an unscoped GitHub App installation token. A user with push access to any repository within the GitHub App installation can craft a PipelineRun containing a remote task annotation that references a private repository, causing the system to expose the contents of private repository Tekton definitions. The vulnerability results in a read-only confidentiality breach, allowing sensitive repository content disclosure without providing write access. Exploitation requires only push access to at least one repository within the GitHub App installation, with no additional privileges or complex conditions required. This issue impacts affected versions of the Pipelines-as-Code package before the security fixes were applied.

RECOMMENDATIONS:

  • We recommend you to update github.com/openshift-pipelines/pipelines-as-code to below version:
  • https://github.com/advisories/GHSA-6f2p-296r-cc28

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A Tekton Pipelines-as-Code vulnerability CVE-2026-54168 with a CVSS score of 6.5 allows unauthorized access to private repositories through remote task resolution when configured with an unscoped GitHub App installation token. A user with push access to any repository within the GitHub App installation can craft a PipelineRun containing a remote task annotation that references a private repository, causing the system to expose the contents of private repository Tekton definitions. The vulnerability results in a read-only confidentiality breach, allowing sensitive repository content disclosure without providing write access. Exploitation requires only push access to at least one repository within the GitHub App installation, with no additional privileges or complex conditions required. This issue impacts affected versions of the Pipelines-as-Code package before the security fixes were applied.

RECOMMENDATIONS:

  • We recommend you to update github.com/openshift-pipelines/pipelines-as-code to below version:
  • https://github.com/advisories/GHSA-6f2p-296r-cc28

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu