GO · JUNE 2026 · EARLY WARNING

Openshift Migration Advisor Agent-API Flaw: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
github.com/kubev2v/migration-planner (go)
Affected versions
< 0.13.5
Patched version
Not yet available
GHSA-2FQW-7C6R-2CQ6

An early warning has been issued for a flaw in the Openshift Migration Advisor agent-API that could allow an authenticated attacker to manipulate data across different tenants. This could result in unauthorized overwriting of victim inventory, planting of malicious credential URLs, or corruption of migration assessments.

What happened

An early warning has been issued for a flaw in the Openshift Migration Advisor agent-API that could allow an authenticated attacker to manipulate data across different tenants. This could result in unauthorized overwriting of victim inventory, planting of malicious credential URLs, or corruption of migration assessments. The flaw is due to the agent-API failing to validate the JWT source_id claim, which allows cross-tenant data manipulation.

The affected component is github.com/kubev2v/migration-planner (go) with versions less than 0.13.5. The flaw has been tracked under GHSA-2FQW-7C6R-2CQ6 and CVE-2026-53471. The issue was first flagged on June 10, 2026, and is currently under investigation.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If github.com/kubev2v/migration-planner is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using github.com/kubev2v/migration-planner (go) with versions less than 0.13.5.

What should I do right now?

Monitor for updates from the maintainers of github.com/kubev2v/migration-planner and apply patches as they become available. Ensure that your version of github.com/kubev2v/migration-planner is 0.13.5 or higher.

Is this flaw being exploited in the wild?

There is no confirmed report of this flaw being exploited in the wild at this time.

Sources

Join the 0Day waitlist →

← Back to all threats