Executive brief
Kubetail is a dashboard used to view real-time logs from Kubernetes clusters. A security flaw allows a malicious website to hijack a user's active session and stream their container logs to an attacker-controlled server. This could lead to the exposure of sensitive information, such as credentials, internal hostnames, or customer data accidentally recorded in application logs.
Technical details
A Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in Kubetail due to missing validation of the 'Origin' header during WebSocket connection upgrades. An attacker can exploit this by tricking an authenticated user into visiting a malicious webpage, which then establishes a WebSocket connection to the Kubetail dashboard (either on localhost or a cluster Ingress). Because browsers automatically include ambient credentials (like cookies or Basic Auth) in the upgrade request, the attacker can successfully authenticate and stream real-time container logs. This provides read-only access to any logs the victim is authorized to view. The issue is fixed in Dashboard v0.14.0, Helm Chart v0.23.0, and CLI v0.16.0.
Affected products
- Kubetail kubetail-dashboard < 0.14.0
- Kubetail kubetail/kubetail (Helm Chart) < 0.23.0
- Kubetail kubetail (CLI) < 0.16.0
Timeline
- 2026-05-01: disclosed: Initial disclosure by maintainers
- 2026-05-07: advisory: GitHub Advisory published
- 2026-05-14: patched: NVD publication and final updates