SCA: security update for github.com/openshift-pipelines/pipelines-as-code (GHSA-f5f4-3hh4-f54m)

high Tenable Self-Hosted Container Security Plugin ID 446141

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories.
Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as
the API host while processing webhook events containing an installation.id, before webhook signature
validation or confirmation that the host matches the repository URL in the signed payload. An
unauthenticated attacker who can reach the webhook endpoint can select an attacker-controlled host and
cause the controller to send a locally signed GitHub App JWT to that service. The exposed JWT may be used
to attempt to mint installation access tokens during its validity window, subject to the GitHub App
installation and permissions. The incoming webhook installation-lookup path is also affected, but
exploitation of that path requires the valid incoming webhook secret for the target Repository CR. This
issue is fixed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0. (CVE-2026-54167)

Solution

Update the github.com/openshift-pipelines/pipelines-as-code library and its related packages to version 0.37.8 or later.

See Also

https://github.com/advisories/GHSA-f5f4-3hh4-f54m

Plugin Details

Severity: High

ID: 446141

Version: Revision 1.2

Type: Local

Family: SCA Checks

Published: 8/20/2026

Updated: 9/16/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 51.67

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:P/A:N

CVSS Score Source: CVE-2026-54167

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/20/2026

Vulnerability Publication Date: 8/20/2026

Reference Information

CVE: CVE-2026-54167

cwe: CWE-345