GITHUB-ACTIONS · AUGUST 2026 · EARLY WARNING

Tekton Pipelines-as-Code Vulnerability: Unauthorized Access Risk

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
tekton (github-actions)
Patched version
v0.48.0
GHSA-6F2P-296R-CC28

An early warning has been issued for a vulnerability in Tekton Pipelines-as-Code that reportedly allows unauthorized access to private repositories due to an unscoped GitHub App installation token.

What happened

Tekton Pipelines-as-Code is under investigation for a vulnerability that appears to allow unauthorized access to private repositories. This is due to an unscoped GitHub App installation token, which can lead to a read-only confidentiality breach. The issue was first flagged on 2026-08-20T18:36:40+00:00. The vulnerability is tracked under GHSA-6F2P-296R-CC28 and has a high severity rating.

The vulnerability is not yet confirmed to be exploited in the wild. It is recommended to upgrade to Tekton Pipelines-as-Code v0.48.0 or later and limit GitHub App installations to only required repositories to mitigate potential risks.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If tekton is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Tekton Pipelines-as-Code, you may be affected. The specific version range is not yet published, so it is recommended to upgrade to v0.48.0 or later as a precaution.

What should I do right now?

Upgrade to Tekton Pipelines-as-Code v0.48.0 or later and limit GitHub App installations to only required repositories.

Is there an official fix available?

Yes, the patched version is v0.48.0. It is recommended to upgrade to this version or later.

Sources

Join the 0Day waitlist →

← Back to all threats