Every node runs a kubelet that exposes an API, usually on 10250, to manage the node's pods. Where it allows anonymous access or the node's authorization is lax, it lists pods and runs commands inside them directly, which is code execution in any container on the node, bypassing the API server and its RBAC.
K=https://<node>:10250
curl -sk $K/pods | jq '.items[].metadata | {namespace,name}'
# Run a command in a container (namespace, pod, container from /pods)
curl -sk -X POST "$K/run/<ns>/<pod>/<container>" -d "cmd=id"
Exploitation notes#
/podsis the inventory;/runand/execgive execution inside those containers, often including more privileged workloads than your own.- Target pods with powerful service-account tokens or host mounts; exec in, then steal the token or use the mount.
- Reaching
10250needs node network access, from a node foothold or a Host network namespace pod.