Junglewise Threat Intelligence

CVE-2025-29922: GO-2025-3538 - kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace in github.com/kcp-dev/k

CVE-2025-29922 · Severity: low · CVSS 3.1 · Published 2025-03-25

Technologies: github.com/kcp-dev/kcp (Go). Vendors: Go.

Executive brief

kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace in github.com/kcp-dev/kcp

Affected products

  • Go github.com/kcp-dev/kcp

Related threats