CWE-322: SSH host key verification disabled — 4 instances of InsecureIgnoreHostKey, K3S_TOKEN exposed
Author: LeoWSY-hashblueCreated Jun 16, 2026Updated Jun 16, 2026
Summary
4 separate locations hardcode ssh.InsecureIgnoreHostKey(). K3S_NODE_TOKEN and k3s installer scripts transmitted over unverified SSH. Full K3s cluster bootstrap process can be MITM hijacked.
Impact
K3s cluster bootstrap credentials exposed. Attacker can compromise entire K3s deployment during setup.
Remediation
Implement proper host key verification with known_hosts. Full report available.
Source: alexellis/k3sup