Cloudpirates Io · Cloudpirates Open Source Helm Charts · CVE-2026-45131
**Name of the Vulnerable Software and Affected Versions**
CloudPirates Open Source Helm Charts versions prior to commit fcf9302
**Description**
A GitHub Actions workflow in the `pull-request.yaml` file executes attacker-controlled code from fork pull requests within a privileged context. This allows for the exfiltration of repository secrets, such as Docker Hub credentials and tokens, without requiring approval from a maintainer.
**Recommendations**
Update to the version containing commit fcf9302.