CVE-2026-47680
Received Received - Intake

Path Traversal in Flux source-controller

Vulnerability report for CVE-2026-47680, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: GitHub, Inc.

Description

The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. In versions 0.0.17 through 1.8.4, an actor with the ability to influence the contents of a bucket referenced by a `Bucket` resource can cause source-controller to write fetched object data to paths outside the per-reconciliation working directory. The corruption surface is bounded by source-controller's own and downstream Flux controllers' digest verification: source-controller verifies stored artifact digests during reconciliation and rebuilds on divergence; consumers (kustomize-controller, helm-controller) verify the digest of fetched artifacts and reject mismatches. These checks prevent a manipulated artifact from reaching the cluster, but an attacker can still write files anywhere the source-controller pod has permission to write. Separately, a user with permission to create or update `GitRepository` resources can cause source-controller to test for the existence of paths outside the cloned repository. Because the result is exposed via the resource's status, this allows limited enumeration of file paths on the controller pod. This surface exists only on source-controller v1.6.0 and later, where the sparse-checkout feature was introduced. This vulnerability was fixed in source-controller v1.8.5. There is no in-product workaround. Users should upgrade to a patched version. As a defense-in-depth measure for the GitRepository sparse-checkout surface, a `ValidatingAdmissionPolicy` (or a third-party policy engine such as Kyverno or OPA Gatekeeper) can be deployed to reject `GitRepository` resources whose `.spec.sparseCheckout` entries contain `..` or absolute path segments.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
fluxcd source-controller 0.0.17
fluxcd source-controller From 0.0.17 (inc) to 1.8.4 (inc)
fluxcd source-controller From 1.6.0 (inc)
fluxcd source-controller 1.8.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The source-controller in Kubernetes manages artifact acquisition from external sources like Git or Helm repositories. In versions 0.0.17 through 1.8.4, an attacker with access to influence a referenced bucket can cause the controller to write data to unauthorized paths outside its working directory. This is limited by digest verification checks that prevent manipulated artifacts from reaching the cluster, but files can still be written anywhere the controller pod has permissions.

Detection Guidance

Detecting this vulnerability requires checking the version of the source-controller in your Kubernetes cluster. Run: kubectl get pods -n flux-system -l app=source-controller -o jsonpath='{.items[*].metadata.labels.version}' to verify if the version is between 0.0.17 and 1.8.4. If so, the system is vulnerable.

Impact Analysis

An attacker could write files to unauthorized locations on the system where the source-controller pod runs, potentially leading to data corruption or unauthorized access. For GitRepository resources, an attacker with update permissions could enumerate file paths on the controller pod by exploiting sparse-checkout features.

Mitigation Strategies

Upgrade the source-controller to version 1.8.5 or later immediately. Use: kubectl set image deployment/source-controller manager=ghcr.io/fluxcd/source-controller:v1.8.5 -n flux-system. Additionally, for GitRepository sparse-checkout, deploy a ValidatingAdmissionPolicy to block resources with .. or absolute paths in .spec.sparseCheckout.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47680. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart