GHSA-rp7v-4384-hfrp

Suggest an improvement
Source
https://github.com/advisories/GHSA-rp7v-4384-hfrp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-rp7v-4384-hfrp/GHSA-rp7v-4384-hfrp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rp7v-4384-hfrp
Aliases
Published
2026-04-24T16:37:12Z
Modified
2026-06-25T23:11:47Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
k8sGPT has Prompt Injection through its k8sGPT-Operator
Details

Summary

In the auto-remediation pipeline, object_to_execution.go was deserializing the AI-generated YAML directly into a Deployment object, but there was lack of validation from the original Deployment object.

Details

This issue was fixed after coordination with Alex Jones.

PoC

To minimize the impact, the PoC of this vulnerability wasn't released, but was shared with the maintainers.

Database specific
{
    "cwe_ids":  [
        "CWE-20",
        "CWE-502",
        "CWE-915"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-24T16:37:12Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Go / github.com/k8sgpt-ai/k8sgpt

Package

Name
github.com/k8sgpt-ai/k8sgpt
View open source insights on deps.dev
Purl
pkg:golang/github.com/k8sgpt-ai/k8sgpt

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.32

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-rp7v-4384-hfrp/GHSA-rp7v-4384-hfrp.json"