Impact
Kata Containers permits pod users to supply the io.katacontainers.config_path annotation, which points to a TOML configuration file stored on the host. The runtime does not validate the path and loads the referenced file without restriction. An attacker who can place a file at a host‑visible location can craft a configuration that selects an attacker‑controlled hypervisor or virtio‑fs binary, causing the runtime to execute that binary with root privileges on the host. This bypasses container isolation and results in arbitrary code execution.
Affected Systems
The affected product is the Kata Containers runtime prior to version 4.0.0. All releases of kata-runtime that allow the io.katacontainers.config_path annotation are vulnerable. No other vendor or product variants are listed in the CVE data.
Risk and Exploitability
The CVSS score of 9.6 signals a critical severity. No EPSS score is available, so the current likelihood of exploitation cannot be quantified, and the issue is not listed in CISA KEV. Based on the description, it is inferred that an attacker must be able to create or modify a pod and write a file to a host‑visible path; thus the attack vector requires cluster‑level or privileged access within the orchestration environment.
OpenCVE Enrichment