Junglewise Threat Intelligence

CVE-2026-42457: Loft vCluster Platform Stored XSS in templateRef name field

CVE-2026-42457 · Severity: critical · CVSS 9 · Published 2026-05-14

Executive brief

vCluster Platform, a tool used to manage virtual Kubernetes clusters and multi-tenant environments, is vulnerable to a security flaw that allows an attacker to run malicious scripts in other users' browsers. By naming a specific resource with a malicious script, an attacker can trick the system into executing that script when an administrator views the resource. This could allow a low-privileged user to steal administrative credentials, create new administrator accounts, and take full control of the platform.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in vCluster Platform (formerly Loft) within the 'name' field of a 'templateRef' in 'SpaceInstance' objects. An authenticated attacker with permissions to create namespaces can inject a malicious JavaScript payload into this field. When an administrative user interacts with the UI (such as hovering over the affected namespace icon), the payload executes in their browser context. The exploit can access the 'loft_access_key' from local storage, allowing the attacker to perform actions on behalf of the victim, including creating new Global-Admin users via the /v1/users API endpoint. The vulnerability is fixed in versions 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0.

Affected products

  • Loft Labs vCluster Platform < 4.4.3, < 4.5.5, < 4.6.2, < 4.7.1, < 4.8.0

Timeline

  • 2026-04-30: advisory: GitHub advisory published by vendor
  • 2026-05-14: disclosed: CVE published to NVD

References