Remote Code Execution Vulnerability in Kube Resource Orchestrator
CVE-2025-48710
4.1MEDIUM
What is CVE-2025-48710?
The Kube Resource Orchestrator allows users with permission to create or modify ResourceGraphDefinition resources to inject arbitrary container images. This capability can lead to a confused-deputy scenario where unauthorized images, potentially controlled by attackers, are deployed and executed within the Kubernetes cluster, posing significant security risks and enabling unauthenticated remote code execution on cluster nodes.
Affected Version(s)
kro 0.1.0 < 0.2.1