Kubernetes Operator Vulnerability in FluxCD Source-Controller Product by Weaveworks
CVE-2026-47680
What is CVE-2026-47680?
The FluxCD source-controller, a Kubernetes operator responsible for acquiring artifacts from external sources, is vulnerable to a path traversal issue. In affected versions, an actor able to modify the contents of a referenced S3-compatible bucket can prompt the source-controller to write data to unauthorized paths outside its designated working directory. Although the integral digest verification protects against sending manipulated artifacts to the cluster, the source-controller can write to any location it has permission to access. In versions 1.6.0 and later, users with the ability to create or update GitRepository resources can also enumerate file paths beyond the cloned repository, compromising the security of the environment. The vulnerability has been addressed in version 1.8.5, and users are strongly encouraged to update to the latest version to mitigate potential risks.
Affected Version(s)
source-controller >= 0.0.17, < 1.8.5
