Junglewise Threat Intelligence

CVE-2026-40938: Tekton Pipelines argument injection in Git resolver revision parameter

CVE-2026-40938 · Severity: high · CVSS 7.5 · Published 2026-04-21

Technologies: github.com/tektoncd/pipeline (Go), Tekton Pipelines, Linuxfoundation Tekton Pipelines. Vendors: Go, Tekton, Linuxfoundation.

Executive brief

Tekton Pipeline is a framework for creating continuous integration and delivery (CI/CD) systems. A vulnerability in its Git resolver allows an attacker to execute malicious code on the system by providing a specially crafted revision parameter. This could lead to the theft of sensitive cluster-wide secrets, potentially allowing an attacker to take control of the entire cloud environment.

Technical details

The Tekton Git resolver fails to sanitize the 'revision' parameter before passing it as a positional argument to 'git fetch'. An attacker can inject git flags such as '--upload-pack' by starting the revision string with a hyphen. When combined with the resolver's support for local filesystem paths (URLs starting with '/'), this allows the execution of arbitrary binaries present on the resolver pod. Because the resolver's ServiceAccount typically has cluster-wide permissions to read Secrets, successful exploitation allows for full secret exfiltration and subsequent privilege escalation. Patches are available in versions 1.11.1, 1.9.3, 1.6.2, 1.3.4, and 1.0.2.

Affected products

  • TektonCD Tekton Pipeline >= 1.10.0, < 1.11.1; >= 1.7.0, < 1.9.3; >= 1.4.0, < 1.6.2; >= 1.2.0, < 1.3.4; >= 1.0.0, < 1.0.2

Timeline

  • 2026-04-21: disclosed
  • 2026-04-21: advisory

References

Related threats