highVulnerability
GHSA-rp7v-4384-hfrp
### Summary In the auto-remediation pipeline, `object_to_execution.go` was deserializing the AI-generated YAML directly into a Deployment object, but there was lack of validation from the original Deployment object. ### Details This issue was fixed after coordination with Alex Jones. ### PoC To minimize the impact, the PoC of this vulnerability wasn't released, but was shared with the maintainers.
Properties
- ghsa_id
- GHSA-rp7v-4384-hfrp
- severity
- high
- summary
- k8sGPT has Prompt Injection through its k8sGPT-Operator
- cve_id
- GHSA-rp7v-4384-hfrp
- is_ghsa_only
- true
- ghsa_published
- 2026-04-24T16:37:12Z
- source_url
- https://github.com/advisories/GHSA-rp7v-4384-hfrp
- ghsa_updated
- 2026-04-24T16:37:15Z
Related Entities (6)
VULNERABLE_TO (1)
←[Software]go/github.com/k8sgpt-ai/k8sgpt
AFFECTS (1)
→[Software]go/github.com/k8sgpt-ai/k8sgpt
HAS_WEAKNESS (3)
→[Weakness]Improperly Controlled Modification of Dynamically-Determined Object Attributes
→[Weakness]Improper Input Validation
→[Weakness]Deserialization of Untrusted Data
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph