PT-2025-52724 · Keda · Keda

Jorge Turrado

·

Published

2025-12-22

·

Updated

2026-01-08

·

CVE-2025-68476

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions KEDA versions prior to 2.17.3 KEDA versions prior to 2.18.3
Description KEDA is a Kubernetes-based Event Driven Autoscaling component. A flaw exists in KEDA that could allow an attacker with permissions to create or modify a TriggerAuthentication resource to read arbitrary files from the node's filesystem where the KEDA pod resides. This is due to insufficient path validation when loading the Service Account Token specified in spec.hashiCorpVault.credential.serviceAccount. The attacker can direct the file's content to a server they control as part of the Vault authentication request, potentially exfiltrating sensitive system information like secrets, keys, or files such as /etc/passwd. This issue affects any KEDA resource using TriggerAuthentication with HashiCorp Vault authentication.
Recommendations Update KEDA to version 2.17.3 or later. Update KEDA to version 2.18.3 or later.

Exploit

Fix

Incorrect Authorization

Path traversal

Weakness Enumeration

Related Identifiers

AZL-72868
CVE-2025-68476
GHSA-C4P6-QG4M-9JMR
GO-2025-4257
SUSE-SU-2026:0037-1

Affected Products

Keda