CVE-2026-54168 PUBLISHED

Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution

Assigner: GitHub_M
Reserved: 11.06.2026 Published: 15.09.2026 Updated: 15.09.2026

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the repository that triggered the event when the App is installed across multiple repositories. A user with push access to one repository can submit a PipelineRun containing a pipelinesascode.tekton.dev/task remote task annotation that targets a private repository in the same installation. When ScopeTokenToListOfRepos returns no explicit scope, the missing triggering repository ID leaves the token able to access the entire installation. Pipelines-as-Code resolves and inlines the remote private task with that token, disclosing the repository's Tekton definitions. The demonstrated impact is read-only and does not provide write access. This issue is fixed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor tektoncd
Product pipelines-as-code
Versions
  • Version < 0.37.8 is affected
  • Version >= 0.38.0, < 0.39.6 is affected
  • Version >= 0.40.0, < 0.42.1 is affected
  • Version >= 0.43.0, < 0.48.0 is affected

References

Problem Types

  • CWE-269: Improper Privilege Management CWE
  • CWE-862: Missing Authorization CWE