# CVE-2026-54168

## Summary

- **CVE ID:** CVE-2026-54168
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-269, CWE-862
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 17, 2026

## Description

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the repository that triggered the event when the App is installed across multiple repositories. A user with push access to one repository can submit a PipelineRun containing a pipelinesascode.tekton.dev/task remote task annotation that targets a private repository in the same installation. When ScopeTokenToListOfRepos returns no explicit scope, the missing triggering repository ID leaves the token able to access the entire installation. Pipelines-as-Code resolves and inlines the remote private task with that token, disclosing the repository's Tekton definitions. The demonstrated impact is read-only and does not provide write access. This issue is fixed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0.

## Affected Products

- tektoncd — pipelines-as-code (< 0.37.8)
- tektoncd — pipelines-as-code (>= 0.38.0, < 0.39.6)
- tektoncd — pipelines-as-code (>= 0.40.0, < 0.42.1)
- tektoncd — pipelines-as-code (>= 0.43.0, < 0.48.0)

## References

- [CNA](https://github.com/tektoncd/pipelines-as-code/security/advisories/GHSA-6f2p-296r-cc28)
- [CNA](https://github.com/tektoncd/pipelines-as-code/commit/001782829e82b83ecb3da903f5a024ca0826b64c)
- [CNA](https://github.com/tektoncd/pipelines-as-code/commit/40813976a77920feaf52671320d6d3c5ff08eb7e)
- [CNA](https://github.com/tektoncd/pipelines-as-code/commit/ac6fded6dfb69ade7197d4eeed6e90ddbe1b79bc)
- [CNA](https://github.com/tektoncd/pipelines-as-code/commit/e0c4a11ea3800ab9d26cf3a8ae92b74cf18527c3)
- [CNA](https://github.com/tektoncd/pipelines-as-code/releases/tag/v0.37.8)
- [CNA](https://github.com/tektoncd/pipelines-as-code/releases/tag/v0.39.6)
- [CNA](https://github.com/tektoncd/pipelines-as-code/releases/tag/v0.42.1)
- [CNA](https://github.com/tektoncd/pipelines-as-code/releases/tag/v0.48.0)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.41%
- **EPSS Percentile:** 35.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._