Kubetier
← Permission Reference
T1

create pods

The gitRepo volume type ran git clone as root on the node.

A crafted repository URL passed arbitrary commands to git for OS-level code execution, T0 on control plane.

Disabled by default since v1.33 and locked off on v1.36, so the kubelet no longer mounts it.

The path applies only to clusters older than 1.33.

Contextual upgrade to T0:

Pod scheduled on a control plane node where /etc/kubernetes admin credentials are readable

CVE-2024-10220↗CVE-2025-1767↗

Note:

Disabled by default in 1.33 and GA-locked off in 1.36; the kubelet refuses to mount any gitRepo volume, so this is dead on modern clusters.

The ext:: example shows the shape of the primitive, not a reproducible exploit: git has refused that transport by default since 2.12, independently of what CVE-2024-10220 turned on.

CVE-2025-1767 is a separate local-repository exposure, not the RCE.

API Group
(core)
Scope
namespaced
Audit Level
Request

Escalation Paths

  1. Create a pod with a gitRepo volume whose repository contains an ext:: command

  2. kubelet runs git clone as root, executing the injected command on the node

  3. Exfiltrate node credentials.

    This is T0 on control plane nodes

Additional rights needed:

none
CVE-2024-10220↗CVE-2025-1767↗

Note:

The gitRepo driver is disabled by default in 1.33 and GA-locked off in 1.36, so the kubelet will not mount it.

The ext:: example shows the shape of the primitive, not a reproducible exploit: git has refused that transport by default since 2.12, independently of what CVE-2024-10220 turned on.

K8s docs ↗
K8s docs ↗