CVE-2026-47680: CWE-23: Relative Path Traversal in fluxcd source-controller
CVE-2026-47680 is a relative path traversal vulnerability in fluxcd source-controller versions 0.0.17 through 1.8.4. It allows an attacker who can influence a referenced bucket to cause the source-controller to write files outside its working directory. Additionally, users with permission to create or update GitRepository resources can enumerate file paths on the controller pod via the sparse-checkout feature introduced in version 1.6.0. The vulnerability was fixed in version 1.8.5. No in-product workaround exists, but admission policies can mitigate the sparse-checkout enumeration risk.
AI Analysis
Technical Summary
The source-controller component of fluxcd, which manages artifact acquisition from external sources, suffers from a relative path traversal vulnerability (CWE-23) in versions 0.0.17 through 1.8.4. An attacker able to influence the contents of a bucket referenced by a Bucket resource can cause the controller to write fetched object data outside its designated working directory. Although digest verification by source-controller and downstream controllers limits the risk of manipulated artifacts reaching the cluster, arbitrary file writes on the controller pod remain possible within its permission scope. Separately, from version 1.6.0 onward, the sparse-checkout feature in GitRepository resources allows limited file path enumeration on the controller pod due to path existence tests exposed in resource status. This vulnerability was addressed in source-controller version 1.8.5. No in-product workaround is available, but deploying a ValidatingAdmissionPolicy or third-party policy engine to restrict sparseCheckout entries can provide defense-in-depth.
Potential Impact
An attacker with the ability to influence bucket contents can write files anywhere the source-controller pod has write permissions, potentially leading to unauthorized file modifications or persistence on the pod. The digest verification mechanisms prevent manipulated artifacts from propagating to the cluster, limiting the risk of cluster compromise via this vector. The sparse-checkout path enumeration vulnerability allows users with GitRepository resource permissions to gain limited knowledge of the pod's filesystem, which could aid further attacks. There are no known exploits in the wild.
Mitigation Recommendations
A fixed version (source-controller v1.8.5) is available and users should upgrade to this or later versions to remediate the vulnerability. There is no in-product workaround. As a defense-in-depth measure for the sparse-checkout path enumeration, administrators can deploy a ValidatingAdmissionPolicy or third-party policy engines such as Kyverno or OPA Gatekeeper to reject GitRepository resources whose .spec.sparseCheckout entries contain relative path segments like '..' or absolute paths.
CVE-2026-47680: CWE-23: Relative Path Traversal in fluxcd source-controller
Description
CVE-2026-47680 is a relative path traversal vulnerability in fluxcd source-controller versions 0.0.17 through 1.8.4. It allows an attacker who can influence a referenced bucket to cause the source-controller to write files outside its working directory. Additionally, users with permission to create or update GitRepository resources can enumerate file paths on the controller pod via the sparse-checkout feature introduced in version 1.6.0. The vulnerability was fixed in version 1.8.5. No in-product workaround exists, but admission policies can mitigate the sparse-checkout enumeration risk.
CVSS v4.0
Score 5.3medium
Affected software
pkg:github/fluxcd/source-controllerRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The source-controller component of fluxcd, which manages artifact acquisition from external sources, suffers from a relative path traversal vulnerability (CWE-23) in versions 0.0.17 through 1.8.4. An attacker able to influence the contents of a bucket referenced by a Bucket resource can cause the controller to write fetched object data outside its designated working directory. Although digest verification by source-controller and downstream controllers limits the risk of manipulated artifacts reaching the cluster, arbitrary file writes on the controller pod remain possible within its permission scope. Separately, from version 1.6.0 onward, the sparse-checkout feature in GitRepository resources allows limited file path enumeration on the controller pod due to path existence tests exposed in resource status. This vulnerability was addressed in source-controller version 1.8.5. No in-product workaround is available, but deploying a ValidatingAdmissionPolicy or third-party policy engine to restrict sparseCheckout entries can provide defense-in-depth.
Potential Impact
An attacker with the ability to influence bucket contents can write files anywhere the source-controller pod has write permissions, potentially leading to unauthorized file modifications or persistence on the pod. The digest verification mechanisms prevent manipulated artifacts from propagating to the cluster, limiting the risk of cluster compromise via this vector. The sparse-checkout path enumeration vulnerability allows users with GitRepository resource permissions to gain limited knowledge of the pod's filesystem, which could aid further attacks. There are no known exploits in the wild.
Mitigation Recommendations
A fixed version (source-controller v1.8.5) is available and users should upgrade to this or later versions to remediate the vulnerability. There is no in-product workaround. As a defense-in-depth measure for the sparse-checkout path enumeration, administrators can deploy a ValidatingAdmissionPolicy or third-party policy engines such as Kyverno or OPA Gatekeeper to reject GitRepository resources whose .spec.sparseCheckout entries contain relative path segments like '..' or absolute paths.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T21:10:38.798Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
- Is Cloud Service
- true
Threat ID: 6aa098c9acd9273b495cca83
Added to database: 09/08/2026, 23:22:49 UTC
Last enriched: 09/08/2026, 23:37:42 UTC
Last updated: 09/09/2026, 00:13:48 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.