---
id: CVE-2024-33394
aliases:
  - GHSA-4q63-mr2m-57hf
  - GO-2024-2816
title: >-
  kubevirt allows a local attacker to execute arbitrary code via a crafted
  command 
summary: >-
  kubevirt allows a local attacker to execute arbitrary code via a crafted
  command 
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
vendor: kubevirt
product: kubevirt.io/kubevirt
ecosystem: go
affected:
  - kubevirt.io/kubevirt <= 1.2.0
published: '2024-05-02'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:13.161569840Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-4q63-mr2m-57hf'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-33394'
  - url: 'https://gist.github.com/HouqiyuA/1b75e23ece7ad98490aec1c887bdf49b'
  - url: 'https://github.com/kubevirt/kubevirt'
tags:
  - osv
  - go
epss: 0.00327
epssPercentile: 0.2305
ingestedAt: '2026-09-12T03:13:01.753Z'
---

## Overview

An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

## Affected packages

- `kubevirt.io/kubevirt <= 1.2.0`

## Remediation

Refer to the advisory for the patched release.
