Openshift Migration Advisor Agent-API Flaw: Early Warning
- Severity
- HIGH
- Affected component
- github.com/kubev2v/migration-planner (go)
- Affected versions
- < 0.13.5
- Patched version
- Not yet available
An early warning has been issued for a flaw in the Openshift Migration Advisor agent-API that could allow an authenticated attacker to manipulate data across different tenants. This could result in unauthorized overwriting of victim inventory, planting of malicious credential URLs, or corruption of migration assessments.
What happened
An early warning has been issued for a flaw in the Openshift Migration Advisor agent-API that could allow an authenticated attacker to manipulate data across different tenants. This could result in unauthorized overwriting of victim inventory, planting of malicious credential URLs, or corruption of migration assessments. The flaw is due to the agent-API failing to validate the JWT source_id claim, which allows cross-tenant data manipulation.
The affected component is github.com/kubev2v/migration-planner (go) with versions less than 0.13.5. The flaw has been tracked under GHSA-2FQW-7C6R-2CQ6 and CVE-2026-53471. The issue was first flagged on June 10, 2026, and is currently under investigation.
What to do about it
- Monitor for updates from the maintainers of github.com/kubev2v/migration-planner.
- Apply patches as they become available.
- Ensure that your version of github.com/kubev2v/migration-planner is 0.13.5 or higher.
- If you are using a version less than 0.13.5, consider upgrading to a patched version as soon as it is available.
- No official fix has been published yet. Monitor the sources below for updates.
How 0Day would have caught this
github.com/kubev2v/migration-planner is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using github.com/kubev2v/migration-planner (go) with versions less than 0.13.5.
What should I do right now?
Monitor for updates from the maintainers of github.com/kubev2v/migration-planner and apply patches as they become available. Ensure that your version of github.com/kubev2v/migration-planner is 0.13.5 or higher.
Is this flaw being exploited in the wild?
There is no confirmed report of this flaw being exploited in the wild at this time.