{"id":"GO-2026-6105","summary":"Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite","details":"Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite","aliases":["GHSA-c534-2w9c-x7fm"],"modified":"2026-08-18T15:00:16.100283578Z","published":"2026-08-18T14:32:29Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6105"},"references":[{"type":"ADVISORY","url":"https://github.com/kite-org/kite/security/advisories/GHSA-c534-2w9c-x7fm"},{"type":"WEB","url":"https://github.com/kite-org/kite/commit/08116eed557f8d6982cc83af0b02991e0f3577d5"},{"type":"WEB","url":"https://github.com/kite-org/kite/commit/69ad938937af8f375a2e183d1a331926ab851d98"},{"type":"WEB","url":"https://github.com/kite-org/kite/pull/638"},{"type":"WEB","url":"https://github.com/kite-org/kite/releases/tag/v0.14.1"}],"affected":[{"package":{"name":"github.com/zxh326/kite","ecosystem":"Go","purl":"pkg:golang/github.com/zxh326/kite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.6.9"},{"fixed":"0.14.1"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6105.json"}}],"schema_version":"1.9.0"}