GHSA-qf34-295c-26v8

Suggest an improvement
Source
https://github.com/advisories/GHSA-qf34-295c-26v8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-qf34-295c-26v8/GHSA-qf34-295c-26v8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qf34-295c-26v8
Aliases
Published
2026-07-14T20:29:32Z
Modified
2026-07-21T19:19:18Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend
Details

Impact

A privilege escalation vulnerability affects Woodpecker instances using the Kubernetes backend.

The pipeline option backend_options.kubernetes.serviceAccountName was passed directly to the pod spec without any admin gating.

Who is impacted: any operator running the Kubernetes backend. Any user with Push permission on a connected repository can run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace, gaining that account's RBAC permissions. If a privileged ServiceAccount is reachable in that namespace, this can lead to secret exfiltration (database credentials, API keys, TLS certs) and full cluster takeover.

Patches

https://github.com/woodpecker-ci/woodpecker/pull/6792

Workarounds

Operators who cannot upgrade immediately can mitigate by any of:

  • Restrict Push access on repositories connected to the Kubernetes-backed instance to trusted users only.
  • Harden the pipeline namespace: ensure no privileged ServiceAccount exists or is bound in the namespace where pipeline pods run; keep the default ServiceAccount minimally privileged.
  • Disable ServiceAccount token automounting for ServiceAccounts that should not be used by pipelines.
  • Enforce an admission policy (e.g. OPA/Gatekeeper, Kyverno, or a ValidatingAdmissionPolicy) that rejects pipeline pods setting an unexpected serviceAccountName.
  • Use a dedicated, isolated namespace per org/instance with no sensitive RBAC bindings.

Resources

  • Vulnerable option introduced in commit 609ba481b5e912f59aaae8ca7bc22b44523c5e37
  • Affected versions: v1.0.0 through v3.15.0
  • Source: pipeline/backend/kubernetes/backend_options.go (field ServiceAccountName), pipeline/backend/kubernetes/pod.go (assigned to pod spec with no gating)
Database specific
{
    "cwe_ids": [
        "CWE-269",
        "CWE-862"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-14T20:29:32Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

Go
go.woodpecker-ci.org/woodpecker/v3

Package

Name
go.woodpecker-ci.org/woodpecker/v3
View open source insights on deps.dev
Purl
pkg:golang/go.woodpecker-ci.org/woodpecker/v3

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.16.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-qf34-295c-26v8/GHSA-qf34-295c-26v8.json"
github.com/woodpecker-ci/woodpecker

Package

Name
github.com/woodpecker-ci/woodpecker
View open source insights on deps.dev
Purl
pkg:golang/github.com/woodpecker-ci/woodpecker

Affected ranges

Type
SEMVER
Events
Introduced
1.0.0
Last Affected
1.0.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-qf34-295c-26v8/GHSA-qf34-295c-26v8.json"
go.woodpecker-ci.org/woodpecker/v2

Package

Name
go.woodpecker-ci.org/woodpecker/v2
View open source insights on deps.dev
Purl
pkg:golang/go.woodpecker-ci.org/woodpecker/v2

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.8.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-qf34-295c-26v8/GHSA-qf34-295c-26v8.json"