Kubernetes Operator Vulnerability in FluxCD Source-Controller Product by Weaveworks
CVE-2026-47680

5.3MEDIUM

Key Information:

Vendor

Fluxcd

Vendor
CVE Published:
8 September 2026

What is CVE-2026-47680?

The FluxCD source-controller, a Kubernetes operator responsible for acquiring artifacts from external sources, is vulnerable to a path traversal issue. In affected versions, an actor able to modify the contents of a referenced S3-compatible bucket can prompt the source-controller to write data to unauthorized paths outside its designated working directory. Although the integral digest verification protects against sending manipulated artifacts to the cluster, the source-controller can write to any location it has permission to access. In versions 1.6.0 and later, users with the ability to create or update GitRepository resources can also enumerate file paths beyond the cloned repository, compromising the security of the environment. The vulnerability has been addressed in version 1.8.5, and users are strongly encouraged to update to the latest version to mitigate potential risks.

Affected Version(s)

source-controller >= 0.0.17, < 1.8.5

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.