OVERVIEW CVE-2026-40938 is a command injection vulnerability in Tekton Pipelines, an open-source Kubernetes-native CI/CD platform. The vulnerability exists in the git resolver component affecting versions 1.0.0 through 1.11.0. The flaw stems from insufficient input validation of the git revision parameter, which is passed directly to git fetch without checking for flag injection characters. When combined with the resolver's permissive handling of local filesystem paths, attackers can inject arbitrary git flags to execute malicious binaries on the resolver pod. SEVERITY The vulnerability has a CVSS score of 7.5 (HIGH) with a network-based attack vector, high attack complexity, and low privilege requirements. The impact is severe: successful exploitation enables arbitrary code execution on the resolver pod, which runs under the tekton-pipelines-resolvers ServiceAccount with cluster-wide read access to all Kubernetes Secrets. This enables complete exfiltration of sensitive cluster data. An attacker requires only the ability to submit ResolutionRequest objects within the cluster, a capability likely available to multiple tenant roles in shared environments. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, with an EPSS score of 0.0007 indicating the vulnerability is in the lowest percentile for real-world exploitation likelihood. The vulnerability is not listed in the Known Exploited Vulnerabilities catalog. However, the high severity and ease of exploitation in multi-tenant clusters warrant prompt patching to version 1.11.1 to prevent potential future attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.11.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.