## Summary Default `kuma-cp` config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. `CorsAllowedDomains: [".*"]` reflects any `Origin`, and `LocalhostIsAdmin: true` promotes requests from `127.0.0.1` to `mesh-system:admin`. A cross-origin `fetch()` from a malicious page returns the admin JWT and signing material. ## Am I affected? You are affected if all of these hold: 1. `kuma-cp` runs with default config (`CorsAllowedDomains: [".*"]` and `LocalhostIsAdmin: true`). 2. The control plane is reachable from a browser on the same machine: - `kuma-cp run` on a developer laptop - Docker `--network host` or port-publish on a workstation - `kubectl port-forward` from a machine that also browses the web 3. The operator visits a page running attacker JavaScript while the control plane is reachable. You are not affected if: - The control plane runs on a Kubernetes cluster accessed via ClusterIP, NodePort, or LoadBalancer from a remote client. - The control plane runs on an SSH-administered VM with no browser on the host. - `KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false` is set (see https://kuma.io/docs/latest/production/secure-deployment/api-server-auth/). - `KUMA_API_SERVER_CORS_ALLOWED_DOMAINS` is set to an explicit allowlist that excludes attacker origins. ## Mitigation 1. Set `KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false` after retrieving the admin token. 2. Set `KUMA_API_SERVER_CORS_ALLOWED_DOMAINS` to an explicit allowlist, for example `http://localhost:5681,http://127.0.0.1:5681`. 3. Do not run `kuma-cp` on a machine where you browse untrusted sites. ## Fix Fixed in [#16416](https://github.com/kumahq/kuma/pull/16416), backported to all supported release branches ([#16423](https://github.com/kumahq/kuma/pull/16423), [#16424](https://github.com/kumahq/kuma/pull/16424), [#16425](https://github.com/kumahq/kuma/pull/16425), [#16426](https://github.com/kumahq/kuma/pull/16426), [#16427](https://github.com/kumahq/kuma/pull/16427)). Changes in patched versions: - `CorsAllowedDomains` default changed from `[".*"]` to `[]` — CORS is now opt-in; set the env var explicitly if you need GUI access. - `LocalhostIsAdmin` hardened: now requires direct loopback `RemoteAddr` and `Host`, and rejects requests carrying proxy-hop headers (`X-Forwarded-For`), cross-site fetch metadata (`Sec-Fetch-Site`), or a non-localhost `Origin`. Upgrade to a patched version: - 2.7.25 - 2.9.15 - 2.11.13 - 2.12.10 - 2.13.5 ## Credits Reported by `eldudareeno`. ## CVSS `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N` = 5.1 Medium.
## Summary Default `kuma-cp` config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. `CorsAllowedDomains: [".*"]` reflects any `Origin`, and `LocalhostIsAdmin: true` promotes requests from `127.0.0.1` to `mesh-system:admin`. A cross-origin `fetch()` from a malicious page returns the admin JWT and signing material. ## Am I affected? You are affected if all of these hold: 1. `kuma-cp` runs with default config (`CorsAllowedDomains: [".*"]` and `LocalhostIsAdmin: true`). 2. The control plane is reachable from a browser on the same machine: - `kuma-cp run` on a developer laptop - Docker `--network host` or port-publish on a workstation - `kubectl port-forward` from a machine that also browses the web 3. The operator visits a page running attacker JavaScript while the control plane is reachable. You are not affected if: - The control plane runs on a Kubernetes cluster accessed via ClusterIP, NodePort, or LoadBalancer from a remote client. - The control plane runs on an SSH-administered VM with no browser on the host. - `KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false` is set (see https://kuma.io/docs/latest/production/secure-deployment/api-server-auth/). - `KUMA_API_SERVER_CORS_ALLOWED_DOMAINS` is set to an explicit allowlist that excludes attacker origins. ## Mitigation 1. Set `KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false` after retrieving the admin token. 2. Set `KUMA_API_SERVER_CORS_ALLOWED_DOMAINS` to an explicit allowlist, for example `http://localhost:5681,http://127.0.0.1:5681`. 3. Do not run `kuma-cp` on a machine where you browse untrusted sites. ## Fix Fixed in [#16416](https://github.com/kumahq/kuma/pull/16416), backported to all supported release branches ([#16423](https://github.com/kumahq/kuma/pull/16423), [#16424](https://github.com/kumahq/kuma/pull/16424), [#16425](https://github.com/kumahq/kuma/pull/16425), [#16426](https://github.com/kumahq/kuma/pull/16426), [#16427](https://github.com/kumahq/kuma/pull/16427)). Changes in patched versions: - `CorsAllowedDomains` default changed from `[".*"]` to `[]` — CORS is now opt-in; set the env var explicitly if you need GUI access. - `LocalhostIsAdmin` hardened: now requires direct loopback `RemoteAddr` and `Host`, and rejects requests carrying proxy-hop headers (`X-Forwarded-For`), cross-site fetch metadata (`Sec-Fetch-Site`), or a non-localhost `Origin`. Upgrade to a patched version: - 2.7.25 - 2.9.15 - 2.11.13 - 2.12.10 - 2.13.5 ## Credits Reported by `eldudareeno`. ## CVSS `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N` = 5.1 Medium.
## Summary Default `kuma-cp` config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. `CorsAllowedDomains: [".*"]` reflects any `Origin`, and `LocalhostIsAdmin: true` promotes requests from `127.0.0.1` to `mesh-system:admin`. A cross-origin `fetch()` from a malicious page returns the admin JWT and signing material. ## Am I affected? You are affected if all of these hold: 1. `kuma-cp` runs with default config (`CorsAllowedDomains: [".*"]` and `LocalhostIsAdmin: true`). 2. The control plane is reachable from a browser on the same machine: - `kuma-cp run` on a developer laptop - Docker `--network host` or port-publish on a workstation - `kubectl port-forward` from a machine that also browses the web 3. The operator visits a page running attacker JavaScript while the control plane is reachable. You are not affected if: - The control plane runs on a Kubernetes cluster accessed via ClusterIP, NodePort, or LoadBalancer from a remote client. - The control plane runs on an SSH-administered VM with no browser on the host. - `KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false` is set (see https://kuma.io/docs/latest/production/secure-deployment/api-server-auth/). - `KUMA_API_SERVER_CORS_ALLOWED_DOMAINS` is set to an explicit allowlist that excludes attacker origins. ## Mitigation 1. Set `KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false` after retrieving the admin token. 2. Set `KUMA_API_SERVER_CORS_ALLOWED_DOMAINS` to an explicit allowlist, for example `http://localhost:5681,http://127.0.0.1:5681`. 3. Do not run `kuma-cp` on a machine where you browse untrusted sites. ## Fix Fixed in [#16416](https://github.com/kumahq/kuma/pull/16416), backported to all supported release branches ([#16423](https://github.com/kumahq/kuma/pull/16423), [#16424](https://github.com/kumahq/kuma/pull/16424), [#16425](https://github.com/kumahq/kuma/pull/16425), [#16426](https://github.com/kumahq/kuma/pull/16426), [#16427](https://github.com/kumahq/kuma/pull/16427)). Changes in patched versions: - `CorsAllowedDomains` default changed from `[".*"]` to `[]` — CORS is now opt-in; set the env var explicitly if you need GUI access. - `LocalhostIsAdmin` hardened: now requires direct loopback `RemoteAddr` and `Host`, and rejects requests carrying proxy-hop headers (`X-Forwarded-For`), cross-site fetch metadata (`Sec-Fetch-Site`), or a non-localhost `Origin`. Upgrade to a patched version: - 2.7.25 - 2.9.15 - 2.11.13 - 2.12.10 - 2.13.5 ## Credits Reported by `eldudareeno`. ## CVSS `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N` = 5.1 Medium.
## Summary Default `kuma-cp` config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. `CorsAllowedDomains: [".*"]` reflects any `Origin`, and `LocalhostIsAdmin: true` promotes requests from `127.0.0.1` to `mesh-system:admin`. A cross-origin `fetch()` from a malicious page returns the admin JWT and signing material. ## Am I affected? You are affected if all of these hold: 1. `kuma-cp` runs with default config (`CorsAllowedDomains: [".*"]` and `LocalhostIsAdmin: true`). 2. The control plane is reachable from a browser on the same machine: - `kuma-cp run` on a developer laptop - Docker `--network host` or port-publish on a workstation - `kubectl port-forward` from a machine that also browses the web 3. The operator visits a page running attacker JavaScript while the control plane is reachable. You are not affected if: - The control plane runs on a Kubernetes cluster accessed via ClusterIP, NodePort, or LoadBalancer from a remote client. - The control plane runs on an SSH-administered VM with no browser on the host. - `KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false` is set (see https://kuma.io/docs/latest/production/secure-deployment/api-server-auth/). - `KUMA_API_SERVER_CORS_ALLOWED_DOMAINS` is set to an explicit allowlist that excludes attacker origins. ## Mitigation 1. Set `KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false` after retrieving the admin token. 2. Set `KUMA_API_SERVER_CORS_ALLOWED_DOMAINS` to an explicit allowlist, for example `http://localhost:5681,http://127.0.0.1:5681`. 3. Do not run `kuma-cp` on a machine where you browse untrusted sites. ## Fix Fixed in [#16416](https://github.com/kumahq/kuma/pull/16416), backported to all supported release branches ([#16423](https://github.com/kumahq/kuma/pull/16423), [#16424](https://github.com/kumahq/kuma/pull/16424), [#16425](https://github.com/kumahq/kuma/pull/16425), [#16426](https://github.com/kumahq/kuma/pull/16426), [#16427](https://github.com/kumahq/kuma/pull/16427)). Changes in patched versions: - `CorsAllowedDomains` default changed from `[".*"]` to `[]` — CORS is now opt-in; set the env var explicitly if you need GUI access. - `LocalhostIsAdmin` hardened: now requires direct loopback `RemoteAddr` and `Host`, and rejects requests carrying proxy-hop headers (`X-Forwarded-For`), cross-site fetch metadata (`Sec-Fetch-Site`), or a non-localhost `Origin`. Upgrade to a patched version: - 2.7.25 - 2.9.15 - 2.11.13 - 2.12.10 - 2.13.5 ## Credits Reported by `eldudareeno`. ## CVSS `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N` = 5.1 Medium.
Update github.com/kumahq/kuma to 2.7.25; github.com/kumahq/kuma to 2.9.15; github.com/kumahq/kuma to 2.11.13; github.com/kumahq/kuma to 2.12.10; github.com/kumahq/kuma to 2.13.5 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanDefault kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin affects github.com/kumahq/kuma (go), github.com/kumahq/kuma (go), github.com/kumahq/kuma (go), github.com/kumahq/kuma (go), github.com/kumahq/kuma (go). Severity is medium. ## Summary Default `kuma-cp` config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. `CorsAllowedDomains: [".*"]` reflects any `Origin`, and `LocalhostIsAdmin: true` promotes requests from `127.0.0.1` to `mesh-system:admin`. A cross-origin `fetch()` from a malicious page returns the admin JWT and signing material. ## Am I affected? You are affected if all of these hold: 1. `kuma-cp` runs with default config (`CorsAllowedDomains: [".*"]` and `LocalhostIsAdmin: true`). 2. The control plane is reachable from a browser on the same machine: - `kuma-cp run` on a developer laptop - Docker `--network host` or port-publish on a workstation - `kubectl port-forward` from a machine that also browses the web 3. The operator visits a page running attacker JavaScript while the control plane is reachable. You are not affected if: - The control plane runs on a Kubernetes cluster accessed via ClusterIP, NodePort, or LoadBalancer from a remote client. - The control plane runs on an SSH-administered VM with no browser on the host. - `KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false` is set (see https://kuma.io/docs/latest/production/secure-deployment/api-server-auth/). - `KUMA_API_SERVER_CORS_ALLOWED_DOMAINS` is set to an explicit allowlist that excludes attacker origins. ## Mitigation 1. Set `KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false` after retrieving the admin token. 2. Set `KUMA_API_SERVER_CORS_ALLOWED_DOMAINS` to an explicit allowlist, for example `http://localhost:5681,http://127.0.0.1:5681`. 3. Do not run `kuma-cp` on a machine where you browse untrusted sites. ## Fix Fixed in [#16416](https://github.com/kumahq/kuma/pull/16416), backported to all supported release branches ([#16423](https://github.com/kumahq/kuma/pull/16423), [#16424](https://github.com/kumahq/kuma/pull/16424), [#16425](https://github.com/kumahq/kuma/pull/16425), [#16426](https://github.com/kumahq/kuma/pull/16426), [#16427](https://github.com/kumahq/kuma/pull/16427)). Changes in patched versions: - `CorsAllowedDomains` default changed from `[".*"]` to `[]` — CORS is now opt-in; set the env var explicitly if you need GUI access. - `LocalhostIsAdmin` hardened: now requires direct loopback `RemoteAddr` and `Host`, and rejects requests carrying proxy-hop headers (`X-Forwarded-For`), cross-site fetch metadata (`Sec-Fetch-Site`), or a non-localhost `Origin`. Upgrade to a patched version: - 2.7.25 - 2.9.15 - 2.11.13 - 2.12.10 - 2.13.5 ## Credits Reported by `eldudareeno`. ## CVSS `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N` = 5.1 Medium.
AI coding agents often install or upgrade packages automatically in go. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/kumahq/kumago | <2.7.25 | 2.7.25 |
| github.com/kumahq/kumago | >=2.9.0,<2.9.15 | 2.9.15 |
| github.com/kumahq/kumago | >=2.11.0,<2.11.13 | 2.11.13 |
| github.com/kumahq/kumago | >=2.12.0,<2.12.10 | 2.12.10 |
| github.com/kumahq/kumago | >=2.13.0,<2.13.5 | 2.13.5 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate github.com/kumahq/kuma to 2.7.25; github.com/kumahq/kuma to 2.9.15; github.com/kumahq/kuma to 2.11.13; github.com/kumahq/kuma to 2.12.10; github.com/kumahq/kuma to 2.13.5 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanDefault kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin affects github.com/kumahq/kuma (go), github.com/kumahq/kuma (go), github.com/kumahq/kuma (go), github.com/kumahq/kuma (go), github.com/kumahq/kuma (go). Severity is medium. ## Summary Default `kuma-cp` config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. `CorsAllowedDomains: [".*"]` reflects any `Origin`, and `LocalhostIsAdmin: true` promotes requests from `127.0.0.1` to `mesh-system:admin`. A cross-origin `fetch()` from a malicious page returns the admin JWT and signing material. ## Am I affected? You are affected if all of these hold: 1. `kuma-cp` runs with default config (`CorsAllowedDomains: [".*"]` and `LocalhostIsAdmin: true`). 2. The control plane is reachable from a browser on the same machine: - `kuma-cp run` on a developer laptop - Docker `--network host` or port-publish on a workstation - `kubectl port-forward` from a machine that also browses the web 3. The operator visits a page running attacker JavaScript while the control plane is reachable. You are not affected if: - The control plane runs on a Kubernetes cluster accessed via ClusterIP, NodePort, or LoadBalancer from a remote client. - The control plane runs on an SSH-administered VM with no browser on the host. - `KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false` is set (see https://kuma.io/docs/latest/production/secure-deployment/api-server-auth/). - `KUMA_API_SERVER_CORS_ALLOWED_DOMAINS` is set to an explicit allowlist that excludes attacker origins. ## Mitigation 1. Set `KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false` after retrieving the admin token. 2. Set `KUMA_API_SERVER_CORS_ALLOWED_DOMAINS` to an explicit allowlist, for example `http://localhost:5681,http://127.0.0.1:5681`. 3. Do not run `kuma-cp` on a machine where you browse untrusted sites. ## Fix Fixed in [#16416](https://github.com/kumahq/kuma/pull/16416), backported to all supported release branches ([#16423](https://github.com/kumahq/kuma/pull/16423), [#16424](https://github.com/kumahq/kuma/pull/16424), [#16425](https://github.com/kumahq/kuma/pull/16425), [#16426](https://github.com/kumahq/kuma/pull/16426), [#16427](https://github.com/kumahq/kuma/pull/16427)). Changes in patched versions: - `CorsAllowedDomains` default changed from `[".*"]` to `[]` — CORS is now opt-in; set the env var explicitly if you need GUI access. - `LocalhostIsAdmin` hardened: now requires direct loopback `RemoteAddr` and `Host`, and rejects requests carrying proxy-hop headers (`X-Forwarded-For`), cross-site fetch metadata (`Sec-Fetch-Site`), or a non-localhost `Origin`. Upgrade to a patched version: - 2.7.25 - 2.9.15 - 2.11.13 - 2.12.10 - 2.13.5 ## Credits Reported by `eldudareeno`. ## CVSS `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N` = 5.1 Medium.
AI coding agents often install or upgrade packages automatically in go. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/kumahq/kumago | <2.7.25 | 2.7.25 |
| github.com/kumahq/kumago | >=2.9.0,<2.9.15 | 2.9.15 |
| github.com/kumahq/kumago | >=2.11.0,<2.11.13 | 2.11.13 |
| github.com/kumahq/kumago | >=2.12.0,<2.12.10 | 2.12.10 |
| github.com/kumahq/kumago | >=2.13.0,<2.13.5 | 2.13.5 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard