๐Ÿ” CVE Alert

CVE-2026-40161

HIGH 7.7

Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 1.0.0 to 1.10.0, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits the token parameter. A tenant with TaskRun or PipelineRun create permission can exfiltrate the shared API token (GitHub PAT, GitLab token, etc.) by pointing serverURL to an attacker-controlled endpoint.

CWE CWE-201
Vendor tektoncd
Product pipeline
Published Apr 21, 2026
Last Updated Apr 21, 2026
Stay Ahead of the Next One

Get instant alerts for tektoncd pipeline

Be the first to know when new high vulnerabilities affecting tektoncd pipeline are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

tektoncd / pipeline
>= 1.0.0, <= 1.10.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/tektoncd/pipeline/security/advisories/GHSA-wjxp-xrpv-xpff github.com: https://github.com/tektoncd/pipeline/issues/9608 github.com: https://github.com/tektoncd/pipeline/issues/9609