« Volver al listado

CVE-2026-54168

Estado: Pendiente de análisisMedia (6.5)—

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the repository that triggered the event when the App is installed across multiple repositories. A user with push access to one repository can submit a PipelineRun containing a pipelinesascode.tekton.dev/task remote task annotation that targets a private repository in the same installation.

Leer descripción completaMostrar menos

When ScopeTokenToListOfRepos returns no explicit scope, the missing triggering repository ID leaves the token able to access the entire installation. Pipelines-as-Code resolves and inlines the remote private task with that token, disclosing the repository's Tekton definitions. The demonstrated impact is read-only and does not provide write access. This issue is fixed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-54168",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-54168",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-17T14:30:42.954463Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "tektoncd",
          "product": "pipelines-as-code",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.37.8"
            },
            {
              "status": "affected",
              "version": ">= 0.38.0, < 0.39.6"
            },
            {
              "status": "affected",
              "version": ">= 0.40.0, < 0.42.1"
            },
            {
              "status": "affected",
              "version": ">= 0.43.0, < 0.48.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-09-15T15:17:17.887",
  "references": [
    {
      "url": "https://github.com/tektoncd/pipelines-as-code/commit/001782829e82b83ecb3da903f5a024ca0826b64c",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/tektoncd/pipelines-as-code/commit/40813976a77920feaf52671320d6d3c5ff08eb7e",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/tektoncd/pipelines-as-code/commit/ac6fded6dfb69ade7197d4eeed6e90ddbe1b79bc",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/tektoncd/pipelines-as-code/commit/e0c4a11ea3800ab9d26cf3a8ae92b74cf18527c3",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/tektoncd/pipelines-as-code/releases/tag/v0.37.8",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/tektoncd/pipelines-as-code/releases/tag/v0.39.6",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/tektoncd/pipelines-as-code/releases/tag/v0.42.1",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/tektoncd/pipelines-as-code/releases/tag/v0.48.0",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/tektoncd/pipelines-as-code/security/advisories/GHSA-6f2p-296r-cc28",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        },
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the repository that triggered the event when the App is installed across multiple repositories. A user with push access to one repository can submit a PipelineRun containing a pipelinesascode.tekton.dev/task remote task annotation that targets a private repository in the same installation. When ScopeTokenToListOfRepos returns no explicit scope, the missing triggering repository ID leaves the token able to access the entire installation. Pipelines-as-Code resolves and inlines the remote private task with that token, disclosing the repository's Tekton definitions. The demonstrated impact is read-only and does not provide write access. This issue is fixed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0."
    }
  ],
  "lastModified": "2026-09-30T17:43:24.057",
  "sourceIdentifier": "security-advisories@github.com"
}