PT-2025-23762 · Kro · Kro

Roi Nisimi

·

Published

2025-06-04

·

Updated

2025-07-03

·

CVE-2025-48710

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions kro (Kube Resource Orchestrator) versions 0.1.0 through 0.2.1
Description The issue allows users with permission to create or modify ResourceGraphDefinition resources to supply arbitrary container images. This can lead to a confused-deputy scenario where kro's controllers deploy and run attacker-controlled images, resulting in unauthenticated remote code execution on cluster nodes.
Recommendations For versions 0.1.0 through 0.2.1, update to version 0.2.1 or later to resolve the issue. As a temporary workaround, consider restricting access to create or modify ResourceGraphDefinition resources to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-48710
GHSA-7633-X85H-5MQH
GO-2025-3741
OPENSUSE-SU-2025:15225-1

Affected Products

Kro