Junglewise Threat Intelligence

Kite Kubernetes proxy path traversal in API endpoints

Severity: medium · CVSS 6.5 · Published 2026-07-24

Technologies: Kite-Org Kite, github.com/zxh326/kite (Go). Vendors: Go.

Executive brief

Kite, a Kubernetes management tool, contains a vulnerability in how it handles proxy requests to cluster resources. An authenticated user with limited access to a single namespace can use specially crafted web requests to bypass security boundaries and view sensitive information across the entire cluster, including secrets and configuration data. This could lead to the exposure of credentials or other private data managed by the Kubernetes environment.

Technical details

A path traversal vulnerability exists in Kite versions 0.6.9 through 0.14.0 due to improper canonicalization of URL paths before authorization. The application performs RBAC checks against the original namespace and resource parameters but subsequently decodes the proxy path and passes it to url.JoinPath, which resolves '..' segments. An attacker with 'get' permissions on pods or services in one namespace can use encoded traversal segments (e.g., %2e%2e/) to reach different Kubernetes API endpoints. This allows the disclosure of cluster-wide resources using Kite's service account permissions. The issue is fixed in version 0.14.1.

Affected products

  • kite-org Kite 0.6.9 - 0.14.0

Timeline

  • 2026-07-19: patched: Fix merged into main branch
  • 2026-07-23: disclosed: Initial advisory publication
  • 2026-07-24: advisory: GitHub reviewed advisory published

References

Related threats