highVulnerability

GHSA-rp7v-4384-hfrp

### Summary In the auto-remediation pipeline, `object_to_execution.go` was deserializing the AI-generated YAML directly into a Deployment object, but there was lack of validation from the original Deployment object. ### Details This issue was fixed after coordination with Alex Jones. ### PoC To minimize the impact, the PoC of this vulnerability wasn't released, but was shared with the maintainers.

Properties

ghsa_id
GHSA-rp7v-4384-hfrp
severity
high
summary
k8sGPT has Prompt Injection through its k8sGPT-Operator
cve_id
GHSA-rp7v-4384-hfrp
is_ghsa_only
true
ghsa_published
2026-04-24T16:37:12Z
source_url
https://github.com/advisories/GHSA-rp7v-4384-hfrp
ghsa_updated
2026-04-24T16:37:15Z

Related Entities (6)

VULNERABLE_TO (1)

[Software]go/github.com/k8sgpt-ai/k8sgpt

AFFECTS (1)

[Software]go/github.com/k8sgpt-ai/k8sgpt

HAS_WEAKNESS (3)

[Weakness]Improperly Controlled Modification of Dynamically-Determined Object Attributes
[Weakness]Improper Input Validation
[Weakness]Deserialization of Untrusted Data

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph