Impact
A GitHub App installation token that is not limited to the repository that triggered the event can be used by a user who has push permissions to one repository in the same installation to request the execution of a PipelineRun that references a remote task in a different, private repository. When the pipelinesascode.tekton.dev/task annotation points to a private repository, the application resolves and inlines the task using the unscoped token, allowing the remote repository’s Tekton definitions to be read. The vulnerability is an authorization flaw consistent with CWE-269 and CWE-862 and provides read‑only access to private content, but does not grant write capability.
Affected Systems
The issue affects Tekton Pipelines‑as‑Code installations before versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0. It applies when a GitHub App is installed across multiple repositories and an unscoped installation token is created during webhook processing. The problem is specific to the Tekton Pipelines‑as‑Code component and does not apply to other Tekton packages.
Risk and Exploitability
The CVSS score of 6.5 places the vulnerability in the medium severity range, while the EPSS score is < 1%, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires the attacker to have push access to any repository in the installation and to craft a PipelineRun that targets a remote task in a private repository. Once the token is used, the attacker can read the Tekton manifest files of the private repository but cannot modify them.
OpenCVE Enrichment
Github GHSA