PT-2026-25851 · Romeo · Romeo
Virb3
·
Published
2026-03-16
·
Updated
2026-03-27
·
CVE-2026-32737
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Romeo versions prior to 0.2.1
Description
Romeo is a tool designed to measure code coverage for Go applications within GitHub Actions. A misconfigured NetworkPolicy allows a malicious actor to move from the "hardened" namespace to any other Pod, breaking the expected security-by-default behavior and potentially enabling lateral movement. The issue stems from a mis-written NetworkPolicy.
Recommendations
Update to version 0.2.1 or later.
If updates are not possible, manually delete the
inter-ns NetworkPolicy.
Delete any failing network policy prefixed by inter-ns- in the target namespace.Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Romeo