Vulnerability Report: GO-2025-3741
- CVE-2025-48710, GHSA-7633-x85h-5mqh
- Affects: github.com/kro-run/kro
- Published: Jun 09, 2025
- Unreviewed
kro Confused Deputy vulnerability in github.com/kro-run/kro
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-7633-x85h-5mqh or https://nvd.nist.gov/vuln/detail/CVE-2025-48710.
Affected Modules
-
PathGo Versions
-
before v0.2.1
Aliases
References
- https://github.com/advisories/GHSA-7633-x85h-5mqh
- https://nvd.nist.gov/vuln/detail/CVE-2025-48710
- https://github.com/kro-run/kro/compare/v0.2.1...v0.2.2
- https://orca.security/resources/blog/kubernetes-crd-abstraction-risks-kro
- https://vuln.go.dev/ID/GO-2025-3741.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.