#461·k3sup

CWE-322: SSH host key verification disabled — 4 instances of InsecureIgnoreHostKey, K3S_TOKEN exposed

Author: LeoWSY-hashblueCreated Jun 16, 2026Updated Jun 16, 2026

Summary

4 separate locations hardcode ssh.InsecureIgnoreHostKey(). K3S_NODE_TOKEN and k3s installer scripts transmitted over unverified SSH. Full K3s cluster bootstrap process can be MITM hijacked.

Impact

K3s cluster bootstrap credentials exposed. Attacker can compromise entire K3s deployment during setup.

Remediation

Implement proper host key verification with known_hosts. Full report available.