CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-33211

Critical · CVSS 9.6

Tekton Pipelines — Path Traversal (CWE-22) via git resolver pathInRepo parameter

CVSS
9.6
nvd
EPSS
0.57%
44th pct
KEV
No
Class
oss containerizable
CWE-22, CWE-22

Description

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `ResolutionRequests` (e.g. by creating `TaskRuns` or `PipelineRuns` that use the git resolver) can read arbitrary files from the resolver pod's filesystem, including ServiceAccount tokens. The file contents are returned base64-encoded in `resolutionrequest.status.data`. Versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2 contain a patch.

Search profile — drives PoC discovery

Symbols pathInRepoResolutionRequestresolutionrequest.status.datagit resolverTaskRunPipelineRuntektoncd/pipelinegitresolverResolutionRequests
Keywords CVE-2026-33211Tekton Pipelines path traversaltektoncd pipeline git resolverpathInRepo traversalResolutionRequest path traversalTekton git resolver arbitrary file readTekton ServiceAccount token leaktekton pipeline resolutionrequest exploittekton gitresolver PoC
Versions: 1.0.0 to <1.0.1, <1.3.3, <1.6.1, <1.9.2, <1.10.2

Affected packages

Go github.com/tektoncd/pipeline 1.0.0 → 1.0.1
Go github.com/tektoncd/pipeline 1.1.0 → 1.3.3
Go github.com/tektoncd/pipeline 1.10.0 → 1.10.2
Go github.com/tektoncd/pipeline 1.10.0 → 1.11.1
Go github.com/tektoncd/pipeline 1.4.0 → 1.6.1
Go github.com/tektoncd/pipeline 1.7.0 → 1.9.2

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z