CVE-2026-54168 is a medium-severity (CVSS 6.5) Improper Privilege Management vulnerability in github.com/openshift-pipelines/pipelines-as-code. A fix is available for github.com/openshift-pipelines/pipelines-as-code — see the affected versions and patch details below.
Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution
Exploitation Status
No confirmed exploitation observed yet
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-54168.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2026-54168 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 383,485 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
github.com/openshift-pipelines/pipelines-as-code🐹github.com/openshift-pipelines/pipelines-as-code🐹github.com/openshift-pipelines/pipelines-as-code🐹github.com/openshift-pipelines/pipelines-as-codeReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Go packages — download data is not available via public APIs for these ecosystems.
Description
Impact
When Pipelines-as-Code is configured with a GitHub App installed across multiple repositories, the installation token issued during webhook processing is not scoped to the triggering repository by default. The token retains access to all repositories in the GitHub App installation.
This allows a user with push access to any repository in the installation to craft a PipelineRun with a remote task annotation pointing at a private repository in the same installation:
pipelinesascode.tekton.dev/task: "https://github.com/org/private-repo/blob/main/.tekton/secret-task.yaml"
Pipelines-as-Code resolves and inlines the remote task using the unscoped token, exposing the contents of the private repository's Tekton definitions. This is a read-only confidentiality breach, no write access is exposed.
Patches
The fix extracts the repository ID from the webhook payload during initial parsing so that it is available for later use. It then adds a fallback in the client setup path so that when no explicit scoping configuration is present and ScopeTokenToListOfRepos returns empty, the token is re-issued scoped to the triggering repository's ID rather than retaining access to the entire installation. The initial token remains unscoped so that the extra-repos lookup can still discover and resolve additional repositories when configured.
The fix is available in v0.48.0. Supported backport releases will be added here after release tags are published.
Workarounds
Limit the GitHub App installation to only the repositories that require Pipelines-as-Code. Avoid org-wide installations or mixed-trust installations where repositories with different access requirements share the same GitHub App. This restricts the blast radius of the unscoped token to only the repositories that are explicitly selected during App installation.
Credits
Reported and fixed by the Pipelines-as-Code maintainers.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐹Go | github.com/openshift-pipelines/pipelines-as-code | all versions | 0.37.8go get github.com/openshift-pipelines/pipelines-as-code@v0.37.8 |
| 🐹Go | github.com/openshift-pipelines/pipelines-as-code | ≥ 0.38.0&&< 0.39.6 | 0.39.6go get github.com/openshift-pipelines/pipelines-as-code@v0.39.6 |
| 🐹Go | github.com/openshift-pipelines/pipelines-as-code | ≥ 0.40.0&&< 0.42.1 | 0.42.1go get github.com/openshift-pipelines/pipelines-as-code@v0.42.1 |
| 🐹Go | github.com/openshift-pipelines/pipelines-as-code | ≥ 0.43.0&&< 0.48.0 | 0.48.0go get github.com/openshift-pipelines/pipelines-as-code@v0.48.0 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for github.com/openshift-pipelines/pipelines-as-code, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update github.com/openshift-pipelines/pipelines-as-code to 0.37.8 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-54168 is resolved across your whole dependency graph.
Workarounds
Close the privilege gap rather than the entry point: audit which accounts, roles and service identities can reach the affected operation, drop the component to the least privilege it actually needs, and review file and directory permissions created by earlier installs — a default left in place is what makes this reachable.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
This flaw has a Moderate impact because Pipelines-as-Code GitHub App deployments installed across multiple repositories can issue an installation token that is not restricted to the repository that triggered a webhook. A user with push access to one repository can use a remote-task annotation to read Tekton…
Limit GitHub App installations to only repositories that require Pipelines-as-Code. Avoid organization-wide or mixed-trust installations that combine repositories with different access requirements under one GitHub App installation.Source: Red Hat security advisory for CVE-2026-54168 (CC BY 4.0)
Frequently Asked Questions
Is CVE-2026-54168 in your dependencies?
Find it across Go, including transitive dependencies.