Tekton Pipelines-as-Code Vulnerability: Unauthorized Access Risk
- Severity
- HIGH
- Affected component
- tekton (github-actions)
- Patched version
- v0.48.0
An early warning has been issued for a vulnerability in Tekton Pipelines-as-Code that reportedly allows unauthorized access to private repositories due to an unscoped GitHub App installation token.
What happened
Tekton Pipelines-as-Code is under investigation for a vulnerability that appears to allow unauthorized access to private repositories. This is due to an unscoped GitHub App installation token, which can lead to a read-only confidentiality breach. The issue was first flagged on 2026-08-20T18:36:40+00:00. The vulnerability is tracked under GHSA-6F2P-296R-CC28 and has a high severity rating.
The vulnerability is not yet confirmed to be exploited in the wild. It is recommended to upgrade to Tekton Pipelines-as-Code v0.48.0 or later and limit GitHub App installations to only required repositories to mitigate potential risks.
What to do about it
- Upgrade to Tekton Pipelines-as-Code v0.48.0 or later.
- Limit GitHub App installations to only the required repositories.
- Monitor the primary sources for updates on this vulnerability.
- Consult the primary sources for the latest information on the vulnerability and any official fixes.
How 0Day would have caught this
tekton is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Tekton Pipelines-as-Code, you may be affected. The specific version range is not yet published, so it is recommended to upgrade to v0.48.0 or later as a precaution.
What should I do right now?
Upgrade to Tekton Pipelines-as-Code v0.48.0 or later and limit GitHub App installations to only required repositories.
Is there an official fix available?
Yes, the patched version is v0.48.0. It is recommended to upgrade to this version or later.