CVE-2026-33211Disclosure(linuxfoundation / tekton_pipelines)

LOWCVSS 9.6 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linuxfoundation tekton_pipelines systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `ResolutionRequests` (e.g. by creating `TaskRuns` or `PipelineRuns` that use the git resolver) can read arbitrary files from the resolver pod's filesystem, including ServiceAccount tokens. The file contents are returned base64-encoded in `resolutionrequest.status.data`. Versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2 contain a patch.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tekton_pipelines

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-03-24); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Products
tekton_pipelines

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-03-19: 1Mentions · 2026-03-24: 5Mentions · 2026-03-26: 1PoC Mentioned / Linked · 2026-03-24: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-24: 2Technical Details · 2026-03-26: 103-1903-2403-26
Signal classification3 categories
Disclosure
571.4%
General
114.3%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-191
Disclosure1
2026-03-245
Disclosure3General1Patch1
2026-03-261
Disclosure1
Full discourse7 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    A path traversal vulnerability (CVE-2026-33211) affects the `Tekton Pipelines` git resolver, allowing arbitrary file reading from the resolver pod. Monitor for patches. #Tekton #CI_CD #AppSec https://www.pulsepatch.io/posts/cve-2026-33211-tekton-pipelines-path-traversal

    Post summary

    The tweet announces a newly disclosed path traversal vulnerability in Tekton Pipelines, urging users to stay alert for forthcoming patches; no PoC, exploit code, or active exploitation claims are present.

    0000044
    3 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33211 📊 Severity: 9.6 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33211 #CVE-2026-33211 #CVE #Critical #CyberSecurity #InfoSec https://t.co/AMCw6gKu2V

    Post summary

    The tweet announces a newly disclosed high‑severity CVE (CVE-2026-33211) without providing additional technical details, proof of concept, exploit code, or mitigation information.

    0000026
    111 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33211 Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2,… https://www.cve.org/CVERecord?id=CVE-2026-33211

    Post summary

    The post merely mentions CVE-2026-33211 and lists affected Tekton Pipelines versions, without providing any technical, exploit, or mitigation information.

    00000141
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33211: CRITICAL] Critical vulnerability in Tekton Pipelines git resolver versions 1.0.0 and below allows path traversal, exposing sensitive files. Patch available in versions 1.0.1, 1.3.3, 1.6.1, 1...#cve,CVE-2026-33211,#cybersecurity https://cvefind.com/CVE-2026-33211

    Post summary

    A critical path traversal vulnerability (CVE‑2026‑33211) in Tekton Pipelines git resolver is disclosed, with patches available in newer releases.

    0000050
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33211 - Critical Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekt... https://www.thehackerwire.com/vulnerability/CVE-2026-33211/ https://t.co/VtoGZLpNXy

    Post summary

    The post announces a critical vulnerability in Tekton Pipelines across multiple versions but does not provide PoC, exploitation code, or patch details.

    0000043
    145 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33211: Tekton Pipelines git resolver ha... ServiceAccount token exfiltration via `../../../` in pathInRepo parameter - every Tekton tenant becomes cluster admin w... https://zerodaysignal.com/vulnerability/CVE-2026-33211 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑33211 with technical details on credential exfiltration and provides a link likely containing Proof of Concept code.

    0000048
    165 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A path traversal flaw (CVE-2026-33211) in `Tekton Pipelines` git resolver allows reading arbitrary files from the resolver pod. Assess impact on your #CI_CD systems. #Tekton #Kubernetes https://www.pulsepatch.io/posts/cve-2026-33211-tekton-pipelines-git-resolver-path-traversal

    Post summary

    The tweet announces a path traversal vulnerability (CVE‑2026‑33211) in Tekton Pipelines' Git resolver that permits arbitrary file reads from the resolver pod.

    0000029
    1 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationtekton_pipelines-go-
Applinuxfoundationtekton_pipelines1.0.0go-

Explore more