PT-2026-37207 · Go · Github.Com/K8Sgpt-Ai/K8Sgpt

Publicado

2026-04-24

·

Atualizado

2026-04-24

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Summary

In the auto-remediation pipeline, object to execution.go was deserializing the AI-generated YAML directly into a Deployment object, but there was lack of validation from the original Deployment object.

Details

This issue was fixed after coordination with Alex Jones.

PoC

To minimize the impact, the PoC of this vulnerability wasn't released, but was shared with the maintainers.

Correção

Deserialization of Untrusted Data

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-RP7V-4384-HFRP

Produtos afetados

Github.Com/K8Sgpt-Ai/K8Sgpt