All 2 CVE vulnerabilities found in pipelines-as-code, with AI-generated Chinese analysis, references, and POCs.
Vendor: tektoncd
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-54167 | Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header CWE-345 | 8.2 | High | 2026-09-15 |
| CVE-2026-54168 | Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution CWE-269 | 6.5 | Medium | 2026-09-15 |
All 2 known CVE vulnerabilities affecting pipelines-as-code with full Chinese analysis, references, and POCs where available.