Skip to main content
EPSS 0.8%top 46%

CVE-2026-40938: CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in tektoncd pipeline

0
High
Published: 04/21/2026 (04/21/2026, 20:45:24 UTC)
Source: GCVE Database
Vendor/Project: tektoncd
Product: pipeline

Description

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch without any validation that it does not begin with a - character. Because git parses flags from mixed positional arguments, an attacker can inject arbitrary git fetch flags such as --upload-pack=<binary>. Combined with the validateRepoURL function explicitly permitting URLs that begin with / (local filesystem paths), a tenant who can submit ResolutionRequest objects can chain these two behaviors to execute an arbitrary binary on the resolver pod. The tekton-pipelines-resolvers ServiceAccount holds cluster-wide get/list/watch on all Secrets, so code execution on the resolver pod enables full cluster-wide secret exfiltration. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

Affected versions
>=1.7.0 <1.8.0>=1.0.0 <1.0.2>=1.2.0 <1.3.4>=1.4.0 <1.6.2>=1.7.0 <1.9.3>=1.10.0 <1.11.1>= 1.0.0, < 1.0.2>= 1.2.0, < 1.3.4>= 1.4.0, < 1.6.2>= 1.7.0, < 1.9.3>= 1.10.0, < 1.11.1Red HatRed Hat OpenShift BuildsRed Hat OpenShift Builds 1.8.1amd64registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:d98cd490064b491c1113af559323718744b8ffc5e0ff59866618382f3b8dfb4f_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 18:27:24 UTC

Technical Analysis

CVE-2026-40938 is a command injection vulnerability in Tekton Pipelines, a CI/CD system component used in Red Hat OpenShift Builds. An authenticated user able to submit ResolutionRequest objects can inject malicious commands into the git resolver's revision parameter, which is passed unchecked as a positional argument to the git fetch command. The vulnerability is compounded by the acceptance of repository URLs starting with '/' that point to local filesystem paths, allowing an attacker to execute arbitrary binaries on the resolver pod. Successful exploitation can lead to exfiltration of all cluster-wide secrets, significant information disclosure, and potential privilege escalation or lateral movement within the cluster. The vulnerability is rated high severity with a CVSS v3 base score of 8.5. Red Hat advises upgrading from affected versions to OpenShift Builds 1.8.0.

Potential Impact

An attacker with authentication and the ability to submit ResolutionRequest objects can execute arbitrary code on the resolver pod, leading to full exfiltration of cluster-wide secrets. This compromises the confidentiality and integrity of the OpenShift environment. Depending on kubeconfig contents, attackers may escalate privileges or move laterally within the cluster, increasing the risk of further compromise.

Mitigation Recommendations

Red Hat recommends upgrading existing Red Hat OpenShift Builds installations from affected versions to version 1.8.0, which contains the fix. No alternative mitigations meeting Red Hat's criteria for ease of use, applicability, and stability are currently available. Users should follow the official Red Hat advisory and update promptly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:17546
Cve Count
1
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a23404ae29bf47b50c743d0

Added to database: 06/05/2026, 21:31:54 UTC

Last enriched: 08/16/2026, 18:27:24 UTC

Last updated: 09/10/2026, 19:42:38 UTC

Views: 142

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses