KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API
Published Sep 21, 2026
8.8
HIGHCVSS 3.1
EPSS 0.48%
Description
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actions/nodeupgradejob.go concatenates authenticated user-controlled spec.version and spec.image values into the keadm upgrade edge shell command. A user with permission to create or update NodeUpgradeJob resources can supply shell metacharacters in either field, causing arbitrary commands to execute on targeted edge nodes with the privileges of the upgrade process and compromising node confidentiality, integrity, and availability. This issue is fixed in versions 1.21.2, 1.22.2, and 1.23.1.
Affected products
-
- Version >= 1.12.0, < 1.21.2StatusaffectedConstraints-
- Version >= 1.22.0, < 1.22.2StatusaffectedConstraints-
- Version >= 1.23.0, < 1.23.1StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/kubeedge/kubeedge
Go
Introduced 1.22.0 Fixed 1.22.2github.com/kubeedge/kubeedge
Go
Introduced 1.23.0 Fixed 1.23.1github.com/kubeedge/kubeedge
Go
Introduced 1.12.0 Fixed 1.21.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/kubeedge/kubeedge | 1.22.0 | 1.22.2 |
| Go | github.com/kubeedge/kubeedge | 1.23.0 | 1.23.1 |
| Go | github.com/kubeedge/kubeedge | 1.12.0 | 1.21.2 |
Remediation
No remediation recorded yet.
References (16)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84003 Advisory
- https://github.com/advisories/GHSA-5jpj-293f-rhvj Advisory
- https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.21.md x_refsource_MISC
- https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.22.md x_refsource_MISC
- https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.23.md x_refsource_MISC
- https://github.com/kubeedge/kubeedge/commit/552af457a4c7ce80ea1678ab5889f475b36ea103 x_refsource_MISC
- https://github.com/kubeedge/kubeedge/commit/657b745bebcdd7a221eb34c0aac13231ef12c37f x_refsource_MISC
- https://github.com/kubeedge/kubeedge/commit/b72db7f8a0f7be23261b4349eab33024b2007df0 x_refsource_MISC
- https://github.com/kubeedge/kubeedge/pull/7028 x_refsource_MISC
- https://github.com/kubeedge/kubeedge/pull/7029 x_refsource_MISC
- https://github.com/kubeedge/kubeedge/pull/7030 x_refsource_MISC
- https://github.com/kubeedge/kubeedge/releases/tag/v1.21.2 x_refsource_MISC
- https://github.com/kubeedge/kubeedge/releases/tag/v1.22.2 x_refsource_MISC
- https://github.com/kubeedge/kubeedge/releases/tag/v1.23.1 x_refsource_MISC
- https://github.com/kubeedge/kubeedge/security/advisories/GHSA-5jpj-293f-rhvj x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-62371
Change history (0)
No recorded changes yet.