PT-2025-50882 · Gardenctl · Gardenctl

Published

2025-12-11

·

Updated

2026-01-06

·

CVE-2025-67508

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions gardenctl versions 2.11.0 and below
Description gardenctl is a command-line client for Gardener, used for configuring access to clusters and cloud provider CLI tools. When used with non-POSIX shells like Fish and PowerShell, versions 2.11.0 and below allow an attacker with administrative privileges for a Gardener project to create malicious credential values. These values are placed in infrastructure Secret objects and can break out of the intended string context when evaluated in Fish or PowerShell environments used by Gardener service operators. The issue involves the manipulation of credential values within Secret objects, potentially leading to unauthorized actions.
Recommendations Update to gardenctl version 2.12.0 or later.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-67508
GHSA-FW33-QPX7-RHX2
GO-2025-4232
SUSE-SU-2026:0037-1

Affected Products

Gardenctl