T05 · Unauthorized Access and Privilege Escalation
- Location
guides/01-installation.md:112- Finding
Documentation Grants Unrestricted Kubernetes Cluster-Administrator Privileges
- Content
View full analysis
kubectl create rolebinding admin-binding \ --clusterrole=admin \ --user= \ --namespace= ``` ### Technical Analysis The installation guide binds the plugin ServiceAccount directly to Kubernetes' built-in `cluster-admin` ClusterRole. The troubleshooting guide similarly recommends granting `cluster-admin` to a user whenever an authorization failure occurs. The `cluster-admin` role provides unrestricted access to every Kubernetes API resource and non-resource endpoint. This is substantially broader than the permissions normally required for workload inspection and routine namespace-level operations. It also contradicts the least-privilege recommendations in `SKILL.md`. Because the plugin exposes tools for command execution, workload mutation, namespace management, security inspection, and SSH monitoring, unnecessarily granting it cluster-administrator privileges enlarges the impact of any compromised dependency, unsafe tool call, or attacker-controlled Agent input. ### Attack Path 1. An administrator follows the installation or troubleshooting instructions. 2. The plugin ServiceAccount or user receives the `cluster-admin` role. 3. An attacker compromises the Agent session, supplies a malicious tool request, or exploits behavior in the unavai ...[truncated 841 chars]- Remediation
View remediation
