CVE-2025-1767Medium· 6.5▾ SunlitKubernetes GitRepo Volume Inadvertent Local Repository Access
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
0.5% → 0.6%
A security vulnerability was discovered in Kubernetes that could allow a user with create pod permission to exploit gitRepo volumes to access local git repositories belonging to other pods on the same node. This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.
k8s.io/kubernetes <= 1.32.3Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-5321Medium· 6.1Kubernetes sets incorrect permissions on Windows containers logs
CVE-2023-3676High· 8.8Kubernetes privilege escalation vulnerability
CVE-2020-8561Medium· 4.1Confused Deputy in Kubernetes
CVE-2021-25736Medium· 5.8Kube-proxy may unintentionally forward traffic
CVE-2015-7561Low· 3.1Kubernetes in OpenShift3 Access Control Misconfiguration
CVE-2024-10220High· 8.1Kubernetes kubelet arbitrary command execution