CVE-2026-62371 | KubeEdge up to 1.21.1/1.22.1/1.23.0 NodeUpgradeJob nodeupgradejob.go v1alpha2 NodeUpgradeJob handler spec.version/spec.image os command injection

SecurityVulns

A vulnerability labeled as very critical has been found in KubeEdge up to 1.21.1/1.22.1/1.23.0. This vulnerability affects the function v1alpha2 NodeUpgradeJob handler of the file edge/pkg/taskmanager/actions/nodeupgradejob.go of the component NodeUpgradeJob. The manipulation of the argument spec.version/spec.image results in os command injection.

This vulnerability is known as CVE-2026-62371. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded.VulDB Recent EntriesRead More