Impact
OpenCost, a Kubernetes cost‑monitoring solution, exposes an unauthenticated POST /serviceKey endpoint that accepts an arbitrary key form value. The value is written directly to the GCP service‑account key.json file used by OpenCost for authentication. The attacker controls the contents but not the directory path, filename, or file mode. Overwriting the credential file can cause OpenCost to operate with attacker‑selected credentials or lose the ability to collect cost data, potentially leading to data integrity breaches or denial of service. The flaw also reflects insufficient input validation (CWE‑20) and improper handling of credentials (CWE‑309). Moreover, the endpoint’s wildcard Access‑Control‑Allow‑Origin response permits browser‑assisted requests when the service is reachable from a browser.
Affected Systems
The flaw affects OpenCost releases prior to version 1.121.0. Vendors covered are opencost:opencost, whose products include the core cost‑monitoring component deployed within Kubernetes clusters. Only deployments that expose the /serviceKey endpoint via a network route are vulnerable; internal workloads not exposed to external traffic remain protected by default network policies.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity. Its EPSS score is below 1%, suggesting a very low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. An attacker who can reach the exposed endpoint—via a network client or a browser if the service is reachable—can supply a crafted service‑account key. Successful exploitation would allow the attacker to assume the identity of that service account, granting them the same permissions as the account, or to disrupt OpenCost’s cost‑collection process by removing valid credentials.
OpenCVE Enrichment
Github GHSA