Executive brief
Pepr is a Kubernetes security framework that defaults to cluster-admin RBAC permissions to provide an easy onboarding experience for new users. This default configuration grants overly broad privileges that should not be used in production environments. If developers skip documentation and deploy modules without explicitly scoping permissions, their Kubernetes workloads gain unnecessary administrative access, increasing the risk of privilege escalation or unauthorized resource modification.
Technical details
This is a configuration/design issue in Pepr's RBAC defaults rather than a traditional exploitable vulnerability. Pepr defaults to rbacMode: "admin" which grants cluster-admin privileges to modules for ease of initial deployment. The vulnerability is rooted in overly permissive default RBAC configuration in the rbac.ts asset file, leaving the framework defaulting to unnecessary privileges. While Pepr is a framework and module authors are ultimately responsible for appropriate RBAC scoping, the defaults present a risk if developers proceed without reviewing build options. The fix involves adding log warnings about admin mode and documenting the requirement to use `npx pepr build --rbac-mode=scoped` for production deployments. No active exploitation has been reported.
Affected products
- Defense Unicorns Pepr < 1.0.5
Timeline
- 2026-01-15: disclosed
- 2026-01-16: patched: Fixed in version 1.0.5