---
id: GO-2026-6105
aliases:
  - GHSA-c534-2w9c-x7fm
title: >-
  Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC
  and read cluster-wide resources in github.com/zxh326/kite
summary: >-
  Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC
  and read cluster-wide resources in github.com/zxh326/kite
severity: none
vendor: zxh326
product: github.com/zxh326/kite
ecosystem: go
affected:
  - 'github.com/zxh326/kite >= 0.6.9, < 0.14.1'
patched:
  - github.com/zxh326/kite 0.14.1
published: '2026-08-18'
updated: '2026-08-18'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2026-6105'
references:
  - url: 'https://github.com/kite-org/kite/security/advisories/GHSA-c534-2w9c-x7fm'
  - url: >-
      https://github.com/kite-org/kite/commit/08116eed557f8d6982cc83af0b02991e0f3577d5
  - url: >-
      https://github.com/kite-org/kite/commit/69ad938937af8f375a2e183d1a331926ab851d98
  - url: 'https://github.com/kite-org/kite/pull/638'
  - url: 'https://github.com/kite-org/kite/releases/tag/v0.14.1'
tags:
  - osv
  - go
ingestedAt: '2026-08-18T19:21:37.655Z'
---

## Overview

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite

## Affected packages

- `github.com/zxh326/kite >= 0.6.9, < 0.14.1`

## Remediation

Upgrade to a patched release:

- `github.com/zxh326/kite 0.14.1`
