Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-47680: CWE-23: Relative Path Traversal in fluxcd source-controller

0
Medium
VulnerabilityCVE-2026-47680cvecve-2026-47680cwe-23
Published: 09/08/2026 (09/08/2026, 23:04:50 UTC)
Source: CVE Database V5
Vendor/Project: fluxcd
Product: source-controller

Description

CVE-2026-47680 is a relative path traversal vulnerability in fluxcd source-controller versions 0.0.17 through 1.8.4. It allows an attacker who can influence a referenced bucket to cause the source-controller to write files outside its working directory. Additionally, users with permission to create or update GitRepository resources can enumerate file paths on the controller pod via the sparse-checkout feature introduced in version 1.6.0. The vulnerability was fixed in version 1.8.5. No in-product workaround exists, but admission policies can mitigate the sparse-checkout enumeration risk.

CVSS v4.0

Score 5.3medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
Low
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected software

GitHub Actionsmore threats →ai
fluxcd/source-controller
pkg:github/fluxcd/source-controller
Affected versions
>=0.0.17 <=1.8.4

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 23:37:42 UTC

Technical Analysis

The source-controller component of fluxcd, which manages artifact acquisition from external sources, suffers from a relative path traversal vulnerability (CWE-23) in versions 0.0.17 through 1.8.4. An attacker able to influence the contents of a bucket referenced by a Bucket resource can cause the controller to write fetched object data outside its designated working directory. Although digest verification by source-controller and downstream controllers limits the risk of manipulated artifacts reaching the cluster, arbitrary file writes on the controller pod remain possible within its permission scope. Separately, from version 1.6.0 onward, the sparse-checkout feature in GitRepository resources allows limited file path enumeration on the controller pod due to path existence tests exposed in resource status. This vulnerability was addressed in source-controller version 1.8.5. No in-product workaround is available, but deploying a ValidatingAdmissionPolicy or third-party policy engine to restrict sparseCheckout entries can provide defense-in-depth.

Potential Impact

An attacker with the ability to influence bucket contents can write files anywhere the source-controller pod has write permissions, potentially leading to unauthorized file modifications or persistence on the pod. The digest verification mechanisms prevent manipulated artifacts from propagating to the cluster, limiting the risk of cluster compromise via this vector. The sparse-checkout path enumeration vulnerability allows users with GitRepository resource permissions to gain limited knowledge of the pod's filesystem, which could aid further attacks. There are no known exploits in the wild.

Mitigation Recommendations

A fixed version (source-controller v1.8.5) is available and users should upgrade to this or later versions to remediate the vulnerability. There is no in-product workaround. As a defense-in-depth measure for the sparse-checkout path enumeration, administrators can deploy a ValidatingAdmissionPolicy or third-party policy engines such as Kyverno or OPA Gatekeeper to reject GitRepository resources whose .spec.sparseCheckout entries contain relative path segments like '..' or absolute paths.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-05-19T21:10:38.798Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null
Is Cloud Service
true

Threat ID: 6aa098c9acd9273b495cca83

Added to database: 09/08/2026, 23:22:49 UTC

Last enriched: 09/08/2026, 23:37:42 UTC

Last updated: 09/09/2026, 00:13:48 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses