Executive brief
kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace in github.com/kcp-dev/kcp
Affected products
- Go github.com/kcp-dev/kcp
Junglewise Threat Intelligence
CVE-2025-29922 · Severity: low · CVSS 3.1 · Published 2025-03-25
Technologies: github.com/kcp-dev/kcp (Go). Vendors: Go.
kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace in github.com/kcp-dev/kcp