Vulnerability Report: GO-2025-3885
- CVE-2025-55196, GHSA-fcxq-v2r3-cc8h
- Affects: github.com/external-secrets/external-secrets
- Published: Aug 18, 2025
- Unreviewed
External Secrets Operator's Missing Namespace Restriction Allows Unauthorized Secret Access in github.com/external-secrets/external-secrets
For detailed information about this vulnerability, visit https://github.com/external-secrets/external-secrets/security/advisories/GHSA-fcxq-v2r3-cc8h or https://nvd.nist.gov/vuln/detail/CVE-2025-55196.
Affected Modules
-
PathGo Versions
-
from v0.15.0 before v0.19.2
Aliases
References
- https://github.com/external-secrets/external-secrets/security/advisories/GHSA-fcxq-v2r3-cc8h
- https://nvd.nist.gov/vuln/detail/CVE-2025-55196
- https://github.com/external-secrets/external-secrets/commit/39cdba5863533007b582dc63dd300839326b2f1d
- https://github.com/external-secrets/external-secrets/commit/de40e8f4fa9559c1d770bb674589b285da5ef2d1
- https://github.com/external-secrets/external-secrets/pull/5109
- https://github.com/external-secrets/external-secrets/pull/5133
- https://vuln.go.dev/ID/GO-2025-3885.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.