Description
The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. In versions 0.0.17 through 1.8.4, an actor with the ability to influence the contents of a bucket referenced by a `Bucket` resource can cause source-controller to write fetched object data to paths outside the per-reconciliation working directory. The corruption surface is bounded by source-controller's own and downstream Flux controllers' digest verification: source-controller verifies stored artifact digests during reconciliation and rebuilds on divergence; consumers (kustomize-controller, helm-controller) verify the digest of fetched artifacts and reject mismatches. These checks prevent a manipulated artifact from reaching the cluster, but an attacker can still write files anywhere the source-controller pod has permission to write. Separately, a user with permission to create or update `GitRepository` resources can cause source-controller to test for the existence of paths outside the cloned repository. Because the result is exposed via the resource's status, this allows limited enumeration of file paths on the controller pod. This surface exists only on source-controller v1.6.0 and later, where the sparse-checkout feature was introduced. This vulnerability was fixed in source-controller v1.8.5. There is no in-product workaround. Users should upgrade to a patched version. As a defense-in-depth measure for the GitRepository sparse-checkout surface, a `ValidatingAdmissionPolicy` (or a third-party policy engine such as Kyverno or OPA Gatekeeper) can be deployed to reject `GitRepository` resources whose `.spec.sparseCheckout` entries contain `..` or absolute path segments.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write
Action: Patch
AI Analysis

Impact

The source-controller includes a path traversal flaw (CWE-23) that allows an attacker who can influence a bucket referenced by a Bucket resource to cause the controller to write fetched object data to file paths outside its per‑reconciliation working directory. While the controller performs digest verification of stored artifacts and downstream Flux controllers reject mismatched digests, they do not prevent the source-controller pod from writing files wherever it has filesystem permissions. A separate surface exists for users who can create or update GitRepository resources; they can cause the controller to test for the existence of paths outside the cloned repository and the result is exposed via the resource’s status, allowing limited enumeration of file paths on the controller pod. These capabilities provide an attacker with the ability to write arbitrary files within the controller pod’s filesystem and to discover existing files, which could facilitate further compromise or covert persistence.

Affected Systems

Flux CD source-controller v0.0.17 through v1.8.4 is affected, including the v1.6.0 and later releases that introduced sparse‑checkout support for GitRepository resources. The flaw is present only in these versions and has been fixed in source‑controller v1.8.5.

Risk and Exploitability

The vulnerability has a CVSS score of 5.3, indicating moderate severity. EPSS data is unavailable and the issue is not listed in CISA’s KEV catalog, so the current likelihood of exploitation is unknown. An attacker with the ability to influence the contents of a referenced bucket or to create/update GitRepository resources can exploit the flaw; the attack vector is most likely within the Kubernetes cluster where the source-controller pod runs. Even without exploiting the digests, the ability to write arbitrary files to the pod’s filesystem is a significant risk, especially if the pod runs privileged or has access to sensitive volume mounts. Enumeration of file paths could aid future attacks or reveal additional sensitive data.

Generated by OpenCVE AI on September 9, 2026 at 08:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the source-controller to v1.8.5 or newer to eliminate the path traversal flaw.
  • Deploy a ValidatingAdmissionPolicy (or a policy engine such as Kyverno or OPA Gatekeeper) that rejects GitRepository resources whose .spec.sparseCheckout entries contain '..' or absolute path segments.
  • Configure the source-controller pod’s security context or filesystem permissions to restrict write access to only its designated working directory, preventing accidental or malicious writes to other parts of the pod’s filesystem.

Generated by OpenCVE AI on September 9, 2026 at 08:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jjrm-hr5f-673x Source controller: Improper path handling allows traversal
History

Fri, 11 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Fluxcd
Fluxcd source-controller
Vendors & Products Fluxcd
Fluxcd source-controller

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. In versions 0.0.17 through 1.8.4, an actor with the ability to influence the contents of a bucket referenced by a `Bucket` resource can cause source-controller to write fetched object data to paths outside the per-reconciliation working directory. The corruption surface is bounded by source-controller's own and downstream Flux controllers' digest verification: source-controller verifies stored artifact digests during reconciliation and rebuilds on divergence; consumers (kustomize-controller, helm-controller) verify the digest of fetched artifacts and reject mismatches. These checks prevent a manipulated artifact from reaching the cluster, but an attacker can still write files anywhere the source-controller pod has permission to write. Separately, a user with permission to create or update `GitRepository` resources can cause source-controller to test for the existence of paths outside the cloned repository. Because the result is exposed via the resource's status, this allows limited enumeration of file paths on the controller pod. This surface exists only on source-controller v1.6.0 and later, where the sparse-checkout feature was introduced. This vulnerability was fixed in source-controller v1.8.5. There is no in-product workaround. Users should upgrade to a patched version. As a defense-in-depth measure for the GitRepository sparse-checkout surface, a `ValidatingAdmissionPolicy` (or a third-party policy engine such as Kyverno or OPA Gatekeeper) can be deployed to reject `GitRepository` resources whose `.spec.sparseCheckout` entries contain `..` or absolute path segments.
Title Source controller: Improper path handling allows traversal
Weaknesses CWE-23
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Fluxcd Source-controller
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T13:03:01.568Z

Reserved: 2026-05-19T21:10:38.798Z

Link: CVE-2026-47680

cve-icon Vulnrichment

Updated: 2026-09-09T13:02:43.020Z

cve-icon NVD

Status : Received

Published: 2026-09-08T23:17:24.400

Modified: 2026-09-09T13:20:18.803

Link: CVE-2026-47680

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T02:00:15Z

Weaknesses
  • CWE-23

    Relative Path Traversal