๐Ÿ” CVE Alert

CVE-2026-33211

CRITICAL 9.6

Tekton Pipelines git resolver has path traversal that allows reading arbitrary files from the resolver pod

CVSS Score
9.6
EPSS Score
0.0%
EPSS Percentile
6th

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `ResolutionRequests` (e.g. by creating `TaskRuns` or `PipelineRuns` that use the git resolver) can read arbitrary files from the resolver pod's filesystem, including ServiceAccount tokens. The file contents are returned base64-encoded in `resolutionrequest.status.data`. Versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2 contain a patch.

CWE CWE-22
Vendor tektoncd
Product pipeline
Published Mar 23, 2026
Last Updated Mar 24, 2026
Stay Ahead of the Next One

Get instant alerts for tektoncd pipeline

Be the first to know when new critical vulnerabilities affecting tektoncd pipeline are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

tektoncd / pipeline
>= 1.0.0, < 1.0.1 >= 1.1.0, < 1.3.3 >= 1.4.0, < 1.6.1 >= 1.7.0, < 1.9.2 >= 1.10.0, < 1.10.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/tektoncd/pipeline/security/advisories/GHSA-j5q5-j9gm-2w5c github.com: https://github.com/tektoncd/pipeline/commit/10fa538f9a2b6d01c75138f1ed7ba3da0e34687c github.com: https://github.com/tektoncd/pipeline/commit/318006c4e3a5 github.com: https://github.com/tektoncd/pipeline/commit/3ca7bc6e6dd1d97f80b84f78370d91edaf023cbd github.com: https://github.com/tektoncd/pipeline/commit/961388fcf3374bc7656d28ab58ca84987e0a75ae github.com: https://github.com/tektoncd/pipeline/commit/b1fee65b88aa969069c14c120045e97c37d9ee5e github.com: https://github.com/tektoncd/pipeline/commit/cdb4e1e97a4f3170f9bc2cbfff83a6c8107bc3db github.com: https://github.com/tektoncd/pipeline/commit/ec7755031a183b345cf9e64bea0e0505c1b9cb78