Junglewise Threat Intelligence

CVE-2026-47680: The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositori

CVE-2026-47680 · Severity: medium · CVSS 4 · Published 2026-09-08

Technologies: github.com/fluxcd/source-controller (Go). Vendors: Go.

Executive brief

Flux source-controller, a component used to manage software deployments in Kubernetes, contains a vulnerability in how it handles file paths. An attacker with control over a storage bucket or specific repository settings could write files to unauthorized locations on the controller's system or discover the existence of sensitive files. While built-in security checks prevent these malicious files from being deployed to the wider cluster, the flaw could still be used to disrupt operations or gather information about the internal system environment.

Technical details

The vulnerability consists of two path traversal issues within the Flux source-controller. First, the Bucket reconciler fails to properly validate object paths, allowing an attacker who can influence bucket contents to write data outside the intended working directory. Second, the GitRepository reconciler's sparse-checkout feature (introduced in v1.6.0) allows users with repository update permissions to use '..' or absolute paths to test for the existence of files on the controller pod's local filesystem. While Flux's digest verification prevents manipulated artifacts from being applied to the cluster, an attacker can still achieve arbitrary file writes within the pod's permission scope or perform limited file enumeration. The issues are addressed in version 1.8.5.

Affected products

  • Flux CD source-controller >= 0.0.17, <= 1.8.4

Timeline

  • 2026-06-02: disclosed
  • 2026-06-05: advisory
  • 2026-06-05: patched: Fixed in v1.8.5

References

Related threats