blob: 71f53f5f4eee2cff6a6d7599972e57b3fdbd1d6c [file]
id: GO-2026-5643
modules:
- module: github.com/tektoncd/pipeline
versions:
- introduced: 1.0.0
- fixed: 1.0.2
- introduced: 1.1.0
- fixed: 1.3.4
- introduced: 1.4.0
- fixed: 1.6.2
- introduced: 1.7.0
- fixed: 1.9.3
- introduced: 1.10.0
- fixed: 1.11.1
vulnerable_at: 1.11.0
summary: |-
Tekton Pipelines VolumeMount path restriction bypass via missing
filepath.Clean in github.com/tektoncd/pipeline
cves:
- CVE-2026-40923
ghsas:
- GHSA-rx35-6rhx-7858
references:
- advisory: https://github.com/tektoncd/pipeline/security/advisories/GHSA-rx35-6rhx-7858
- web: https://github.com/tektoncd/pipeline/releases/tag/v1.11.1
source:
id: GHSA-rx35-6rhx-7858
created: 2026-06-25T15:46:14.843373762-04:00
review_status: REVIEWED