—
GO-2026-6105
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite
Quick fix
GO-2026-6105 — github.com/zxh326/kite: upgrade to the fixed version with the command below.
go get github.com/zxh326/kite@v0.14.1Details
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/zxh326/kite
Introduced in:
0.6.9Fixed in: 0.14.1Fix
go get github.com/zxh326/kite@v0.14.1References
- https://github.com/kite-org/kite/security/advisories/GHSA-c534-2w9c-x7fm[ADVISORY]
- https://github.com/kite-org/kite/commit/08116eed557f8d6982cc83af0b02991e0f3577d5[WEB]
- https://github.com/kite-org/kite/commit/69ad938937af8f375a2e183d1a331926ab851d98[WEB]
- https://github.com/kite-org/kite/pull/638[WEB]
- https://github.com/kite-org/kite/releases/tag/v0.14.1[WEB]