CRITICAL🇵🇱 Wersja polska

CVE-2026-33211

CVSS 9.6v3.1pub. 2026-03-24upd. 2026-08-24

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `ResolutionRequests` (e.g. by creating `TaskRuns` or `PipelineRuns` that use the git resolver) can read arbitrary files from the resolver pod's filesystem, including ServiceAccount tokens. The file contents are returned base64-encoded in `resolutionrequest.status.data`. Versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2 contain a patch.

🤖 AI Analysis
How it works

The vulnerability (CWE-22) consists of insufficient validation of the path provided in the `pathInRepo` parameter when handling requests by the git resolver. A tenant with permissions to create `ResolutionRequests` objects — for example by creating `TaskRuns` or `PipelineRuns` using the git resolver — can provide a crafted path containing path traversal sequences (e.g., `../`). As a result, the resolver reads a file outside the intended repository directory, and its contents are returned encoded in base64 format in the `resolutionrequest.status.data` field, accessible to the user.

Impact

An attacker can read arbitrary files from the resolver pod's file system, including Kubernetes ServiceAccount tokens, which may enable privilege escalation and takeover of cluster resources.

Mitigation & patch

Update Tekton Pipelines to one of the patched versions: 1.0.1, 1.3.3, 1.6.1, 1.9.2, or 1.10.2. Patches are available in the project repository on GitHub (tektoncd/pipeline). As a temporary measure, consider restricting permissions to create `ResolutionRequests`, `TaskRuns`, and `PipelineRuns` objects only to trusted users.

Who is affected

Tekton Pipelines in versions from 1.0.0 (inclusive) to versions: 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2 (exclusive) — that is, all versions in the 1.0.x, 1.3.x, 1.6.x, 1.9.x, and 1.10.x branches before the release of the respective patches.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Linuxfoundation Tekton Pipelines

    APP
    Linuxfoundation
    1.0.01.1.0 – 1.3.3 (excl.)1.4.0 – 1.6.1 (excl.)1.7.0 – 1.9.2 (excl.)1.10.0 – 1.10.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-40161HIGH7.7same product

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version...

CVE-2026-40938HIGH7.5same product

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version...

CVE-2026-40923MEDIUM5.4same product

Projekt Tekton Pipelines udostępnia zasoby w stylu k8s do deklarowania pipelinów CI/CD. Przed wersją 1.11.1 ob...

CVE-2026-40924MEDIUM6.5same product

Projekt Tekton Pipelines zapewnia zasoby o stylistyce k8s do deklarowania pipelineów CI/CD. Przed wersją 1.11....

CVE-2026-25542MEDIUM6.5same product

Projekt Tekton Pipelines udostępnia zasoby w stylu k8s do deklarowania pipelinów CI/CD. W wersjach od 0.43.0 d...