<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Katanemo - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/katanemo/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 16:02:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/katanemo/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Exposure of Envoy Admin Interface in Katanemo Plano</title><link>https://feed.craftedsignal.io/briefs/2026-10-katanemo-plano-auth/</link><pubDate>Sun, 11 Oct 2026 16:02:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-katanemo-plano-auth/</guid><description>Katanemo Plano versions 0.4.37 and earlier contain a missing authentication vulnerability on the Envoy admin interface that allows unauthenticated remote attackers to exfiltrate LLM provider API keys.</description><content:encoded><![CDATA[<p>Katanemo Plano versions 0.4.37 and earlier contain a critical missing authentication vulnerability in its Envoy proxy deployment. The Envoy admin interface, which is typically used for diagnostic and configuration tasks, is improperly exposed and bound to all host interfaces on TCP port 9901. This configuration flaw allows any unauthenticated network attacker with connectivity to the interface to query the /config_dump endpoint. This endpoint returns the full proxy configuration in JSON format. Because Katanemo Plano stores LLM provider API keys as plaintext values within the WASM filter configuration, successful exploitation results in the immediate exfiltration of sensitive credentials used to interface with external Large Language Model services. This vulnerability poses a significant risk to organizations relying on Plano for LLM gateway orchestration, as the exposure of these keys could lead to unauthorized cost accumulation or data leakage via downstream service providers.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to steal sensitive API credentials required to access and utilize external LLM providers. This effectively grants the attacker the ability to spoof the organization's identity when interacting with these services, leading to potential unauthorized charges or access to sensitive model interactions. The vulnerability impacts all deployments of Plano version 0.4.37 and older where the Envoy admin port 9901 is reachable via the network.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Restrict network access to TCP port 9901 immediately via host-based firewalls or network access control lists (NACLs) to ensure only authorized management workstations can access the Envoy admin interface.</li>
<li>Monitor network traffic for inbound connections directed at TCP port 9901 from untrusted sources or internal segments not designated for administration.</li>
<li>Rotate all LLM provider API keys configured within the Plano environment, as they must be assumed compromised if the instance has been exposed to an untrusted network.</li>
<li>Upgrade all instances of Katanemo Plano to a patched version beyond 0.4.37 once released by the vendor.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>exposure</category><category>envoy</category><category>credential-theft</category></item></channel></rss>