Executive brief
Fission is a framework for running serverless functions on Kubernetes. A security flaw in how Fission handles environment configurations allows users with basic permissions to bypass safety checks and create highly privileged containers. An attacker could use this to escape the container sandbox, access the underlying host system, and potentially compromise the entire Kubernetes cluster.
Technical details
A privilege escalation vulnerability exists in Fission due to an incomplete fix for previous PodSpec hardening. While Fission validates 'PodSpec' fields, it failed to inspect the standalone 'spec.runtime.container' and 'spec.builder.container' fields in the Environment Custom Resource Definition (CRD). Specifically, the 'Environment.Validate()' function did not call safety checks on these container-level SecurityContexts, and the 'MergeContainer()' function lacked sanitization logic. An attacker with 'environments.fission.io' create/update RBAC can inject 'privileged: true' or dangerous capabilities (e.g., SYS_ADMIN) into these fields. This allows for container escape and host-level access. The issue is fixed in v1.24.0 by adding 'ValidateContainerSafety' to the admission webhook and sanitization to the merge layer.
Affected products
- fission fission <= 1.23.0
Timeline
- 2026-05-26: patched: Fix released in v1.24.0
- 2026-06-10: advisory: NVD published CVE-2026-50566
- 2026-06-30: disclosed: GitHub Advisory GHSA-m63v-2g9w-2w6v published
References
- https://api.github.com/users/HiyokoSauna37
- https://github.com/HiyokoSauna37
- https://api.github.com/users/HiyokoSauna37/gists%7B/gist_id%7D
- https://api.github.com/users/HiyokoSauna37/repos
- https://avatars.githubusercontent.com/u/263803677?v=4
- https://api.github.com/users/HiyokoSauna37/events%7B/privacy%7D