Executive brief
KubeAI is an open-source platform for deploying and managing AI models on Kubernetes. A vulnerability in how it handles model URLs allows an attacker with permissions to create or update models to execute arbitrary commands inside the model's container. This could lead to the theft of sensitive data, such as API keys and service tokens, or allow an attacker to move laterally within the corporate Kubernetes cluster.
Technical details
An OS command injection vulnerability exists in KubeAI's Ollama engine implementation within `internal/modelcontroller/engine_ollama.go`. The `ollamaStartupProbeScript` function uses `fmt.Sprintf` to construct a shell command for Kubernetes startup probes using unsanitized components from the `Model` resource's URL field. Specifically, the `ref` and `modelParam` (from the `?model=` query string) are parsed via a permissive regex that allows shell metacharacters like semicolons and backticks. Because these probes are executed via `bash -c`, an attacker with RBAC permissions to create or update `Model` custom resources can achieve arbitrary code execution within the resulting model server pods. This can be used to exfiltrate service account tokens or environment variables. The issue is addressed in version 0.23.2.
Affected products
- kubeai-project KubeAI <= 0.23.1
Timeline
- 2026-03-31: disclosed
- 2026-04-01: advisory
- 2026-04-01: patched
References
- https://api.github.com/users/romain-deperne
- https://github.com/romain-deperne
- https://api.github.com/users/romain-deperne/gists%7B/gist_id%7D
- https://api.github.com/users/romain-deperne/repos
- https://avatars.githubusercontent.com/u/61591917?v=4
- https://api.github.com/users/romain-deperne/events%7B/privacy%7D