๐Ÿ” CVE Alert

CVE-2026-47680

UNKNOWN 0.0

Source controller: Improper path handling allows traversal

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. In versions 0.0.17 through 1.8.4, an actor with the ability to influence the contents of a bucket referenced by a `Bucket` resource can cause source-controller to write fetched object data to paths outside the per-reconciliation working directory. The corruption surface is bounded by source-controller's own and downstream Flux controllers' digest verification: source-controller verifies stored artifact digests during reconciliation and rebuilds on divergence; consumers (kustomize-controller, helm-controller) verify the digest of fetched artifacts and reject mismatches. These checks prevent a manipulated artifact from reaching the cluster, but an attacker can still write files anywhere the source-controller pod has permission to write. Separately, a user with permission to create or update `GitRepository` resources can cause source-controller to test for the existence of paths outside the cloned repository. Because the result is exposed via the resource's status, this allows limited enumeration of file paths on the controller pod. This surface exists only on source-controller v1.6.0 and later, where the sparse-checkout feature was introduced. This vulnerability was fixed in source-controller v1.8.5. There is no in-product workaround. Users should upgrade to a patched version. As a defense-in-depth measure for the GitRepository sparse-checkout surface, a `ValidatingAdmissionPolicy` (or a third-party policy engine such as Kyverno or OPA Gatekeeper) can be deployed to reject `GitRepository` resources whose `.spec.sparseCheckout` entries contain `..` or absolute path segments.

CWE CWE-23
Vendor fluxcd
Product source-controller
Published Sep 8, 2026
Last Updated Sep 9, 2026
Stay Ahead of the Next One

Get instant alerts for fluxcd source-controller

Be the first to know when new unknown vulnerabilities affecting fluxcd source-controller are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

fluxcd / source-controller
>= 0.0.17, < 1.8.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/fluxcd/source-controller/security/advisories/GHSA-jjrm-hr5f-673x github.com: https://github.com/fluxcd/source-controller/pull/2054 github.com: https://github.com/fluxcd/source-controller/commit/759bd6c451e7cc4327b38f42c8b671980165cb0e