CVE-2025-48710 Information

Description

kro (Kube Resource Orchestrator) 0.1.0 before 0.2.1 allows users (with permission to create or modify ResourceGraphDefinition resources) to supply arbitrary container images. This can lead to a confused-deputy scenario where kro’s controllers deploy and run attacker-controlled images resulting in unauthenticated remote code execution on cluster nodes.

Reference

https://github.com/kro-run/kro/compare/v0.2.1…v0.2.2 https://orca.security/resources/blog/kubernetes-crd-abstraction-risks-kro/

Share on: