Remote Code Execution Vulnerability in Kube Resource Orchestrator
CVE-2025-48710

4.1MEDIUM

Key Information:

Vendor

Kro.run

Status
Vendor
CVE Published:
4 June 2025

What is CVE-2025-48710?

The Kube Resource Orchestrator allows users with permission to create or modify ResourceGraphDefinition resources to inject arbitrary container images. This capability can lead to a confused-deputy scenario where unauthorized images, potentially controlled by attackers, are deployed and executed within the Kubernetes cluster, posing significant security risks and enabling unauthenticated remote code execution on cluster nodes.

Affected Version(s)

kro 0.1.0 < 0.2.1

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48710 : Remote Code Execution Vulnerability in Kube Resource Orchestrator