CVE-2026-54168Medium· 6.5▾ SunlitPipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the repository that triggered the event when the App is installed across multiple repositories. A user with push access to one repository can submit a PipelineRun containing a pipelinesascode.tekton.dev/task remote task annotation that targets a private repository in the same installation. When ScopeTokenToListOfRepos returns no explicit scope, the missing triggering repository ID leaves the token able to access the entire installation. Pipelines-as-Code resolves and inlines the remote private task with that token, disclosing the repository's Tekton definitions. The demonstrated impact is read-only and does not provide write access. This issue is fixed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/openshift-pipelines/pipelines-as-code < 0.37.8github.com/openshift-pipelines/pipelines-as-code >= 0.38.0, < 0.39.6github.com/openshift-pipelines/pipelines-as-code >= 0.40.0, < 0.42.1github.com/openshift-pipelines/pipelines-as-code >= 0.43.0, < 0.48.0Patched in:
github.com/openshift-pipelines/pipelines-as-code 0.37.8github.com/openshift-pipelines/pipelines-as-code 0.39.6github.com/openshift-pipelines/pipelines-as-code 0.42.1github.com/openshift-pipelines/pipelines-as-code 0.48.0Source: https://osv.dev/vulnerability/GHSA-6f2p-296r-cc28
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54167High· 8.2Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories
CVE-2024-1442Medium· 6.0grafana: Improper priviledge managent for users with data source permissions (CVE-2024-1442)
CVE-2026-64753Medium· 6.5A permissions issue was addressed by removing the vulnerable code
CVE-2026-73269Critical· 9.9A flaw was found in the cluster-curator-controller component
CVE-2026-54099High· 8.8A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform
CVE-2026-61549Critical· 9.0Woodpecker is a CI/CD engine