Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path
Published Aug 12, 2026
9.9
CRITICALCVSS 3.1
EPSS 0.65%
Description
Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in api/src/backend/api/v1/serializers.py checked only exec blocks, and POST /api/v1/providers/{id}/connection loaded it through config.load_kube_config_from_dict in prowler/providers/kubernetes/kubernetes_provider.py, causing kubernetes-python CommandTokenSource.token to run the attacker-supplied command through subprocess.Popen on the shared worker. This issue is fixed in version 5.36.0.
Affected products
-
- Version < 5.36.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Prowler-Cloud | Prowler | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://github.com/prowler-cloud/prowler/commit/0b782fcb8c24ece7bd38deede2b8f13d8583e39c x_refsource_MISC
- https://github.com/prowler-cloud/prowler/pull/12091 x_refsource_MISC
- https://github.com/prowler-cloud/prowler/releases/tag/5.36.0 x_refsource_MISC
- https://github.com/prowler-cloud/prowler/security/advisories/GHSA-ccqh-6cjc-wp4j exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/prowler-cloud/prowler/commit/0b782fcb8c24ece7bd38deede2b8f13d8583e39c | x_refsource_MISC | |
| https://github.com/prowler-cloud/prowler/pull/12091 | x_refsource_MISC | |
| https://github.com/prowler-cloud/prowler/releases/tag/5.36.0 | x_refsource_MISC | |
| https://github.com/prowler-cloud/prowler/security/advisories/GHSA-ccqh-6cjc-wp4j | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.