Namespace Label Injection Vulnerability in Capsule Framework by Project Capsule
CVE-2025-55205
9.1CRITICAL
What is CVE-2025-55205?
An injection vulnerability in the Capsule framework allows authenticated tenant users to insert arbitrary labels into essential system namespaces such as kube-system and default, undermining the multi-tenant security model. This flaw could lead to privilege escalation and exploitation of cross-tenant resources through TenantResource selectors. The integrity of Capsule's design is compromised, enabling users to bypass security boundaries set to protect multi-tenant environments. The issue has been resolved in Capsule version 0.10.4.
Affected Version(s)
capsule < 0.10.4