All vulnerabilities

CVE-2026-NONE · GHSA-4pvf-9j6w-8m88

testkube: unauthenticated Streamable HTTP MCP endpoint grants full control of Testkube workflows and execution data

criticalCWE-306
Vendor
kubeshop
Package
github.com/kubeshop/testkube go
Affected
<= dd574c0
Disclosed
2026-08-19
Credit
Avishai Gonen
auth-bypassmcpdocker