A bug in the webhook generator initialization order incorrectly cleared the label-enforcement flag (EnforceLabels) after it was set, resulting in the provider-side check for external-secrets.io/type=webhook being skipped (and the operation to succeed while it should have failed with secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook.
A user with the permission to create webhook generator can set the webhook generator to a victim' secret (which was not previously labelled for webhook's use), and exfiltrate it to a malicious URL.
Until you upgrade, you can reduce risk by:
generators.external-secrets.io/v1alpha1 Webhook via an admission policy);Webhook;external-secrets.io/type=webhook;NetworkPolicy / service mesh egress policy).{
"cwe_ids": [
"CWE-696"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-06T15:29:25Z",
"nvd_published_at": null,
"severity": "HIGH"
}