CVE-2026-93537: Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle directory
A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated Bundle resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured. This affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SUSE Rancher Fleetto a version that resolves this vulnerability.Fixed in 0.16.2 - Upgrade
Upgrade
SUSE Rancher Fleetto a version that resolves this vulnerability.Fixed in 0.15.7 - Upgrade
Upgrade
SUSE Rancher Fleetto a version that resolves this vulnerability.Fixed in 0.14.11 - Upgrade
Upgrade
SUSE Rancher Fleetto a version that resolves this vulnerability.Fixed in 0.13.16 - Upgrade
Upgrade
SUSE Rancher Fleetto a version that resolves this vulnerability.Fixed in 0.12.20
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs Git push access to a repository referenced by a GitRepo resource, or permission to create or modify a GitRepo. It is not described as exploitable by an unauthenticated user with no repository or GitRepo control.
What data could be exposed?
The issue can cause the bundle-processing environment to read files outside the bundle directory and place their contents in a generated Bundle resource. Exposed material may include configuration or credentials that the attacker cannot otherwise read through Kubernetes RBAC, including Helm registry credentials when per-path Helm credentials are configured.
Which Fleet versions need remediation?
Upgrade to Fleet 0.16.2 or later, 0.15.7 or later, 0.14.11 or later, 0.13.16 or later, or 0.12.20 or later, depending on the supported release line in use. Older unsupported versions may also be affected.
What can be done before upgrading?
Restrict who can push bundle content to repositories referenced by GitRepo resources and who can create or modify GitRepo resources. Pay particular attention to environments using per-path Helm credentials, since those credentials can be available to the bundle-processing job.