CVE-2026-62371

high

Description

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actions/nodeupgradejob.go concatenates authenticated user-controlled spec.version and spec.image values into the keadm upgrade edge shell command. A user with permission to create or update NodeUpgradeJob resources can supply shell metacharacters in either field, causing arbitrary commands to execute on targeted edge nodes with the privileges of the upgrade process and compromising node confidentiality, integrity, and availability. This issue is fixed in versions 1.21.2, 1.22.2, and 1.23.1.

References

https://github.com/kubeedge/kubeedge/security/advisories/GHSA-5jpj-293f-rhvj

https://github.com/kubeedge/kubeedge/releases/tag/v1.23.1

https://github.com/kubeedge/kubeedge/releases/tag/v1.22.2

https://github.com/kubeedge/kubeedge/releases/tag/v1.21.2

https://github.com/kubeedge/kubeedge/pull/7030

https://github.com/kubeedge/kubeedge/pull/7029

https://github.com/kubeedge/kubeedge/pull/7028

https://github.com/kubeedge/kubeedge/commit/b72db7f8a0f7be23261b4349eab33024b2007df0

https://github.com/kubeedge/kubeedge/commit/657b745bebcdd7a221eb34c0aac13231ef12c37f

https://github.com/kubeedge/kubeedge/commit/552af457a4c7ce80ea1678ab5889f475b36ea103

https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.23.md

https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.22.md

https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.21.md

Details

Source: Mitre, NVD

Published: 2026-09-21

Updated: 2026-09-24

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00485