Executive brief
Tekton Pipelines is a tool used to automate software building and deployment (CI/CD) within Kubernetes environments. A security flaw in its 'git resolver' component allows a user with basic permissions to trick the system into sending its master authentication tokens (such as GitHub or GitLab access keys) to a server controlled by the attacker. If exploited, this could allow an attacker to gain unauthorized access to private source code repositories and sensitive corporate data.
Technical details
The vulnerability exists in the ResolveAPIGit() function within pkg/resolution/resolver/git/resolver.go. When a user provides a custom 'serverURL' but omits the 'token' parameter, the resolver defaults to using the system-configured Git API token (e.g., GitHub PAT or GitLab token) stored in the controller's secrets. Because the resolver does not validate the user-supplied URL against the system-configured Git server, it transmits the system token in the Authorization header to the attacker-controlled endpoint. This allows a tenant with TaskRun or PipelineRun creation permissions to exfiltrate high-privilege credentials. The fix introduces validation to ensure system tokens are only used with system-configured server URLs.
Affected products
- TektonCD Tekton Pipelines >= 1.0.0, < 1.11.1
Timeline
- 2026-03-17: other: Related architectural issues opened regarding secret namespace handling and access reviews.
- 2026-04-21: advisory: Vendor advisory GHSA-wjxp-xrpv-xpff published.
- 2026-04-21: disclosed: CVE-2026-40161 published.