Two vulnerabilities have been discovered in Kubernetes environments that use the Image Builder tool to create VM images for cluster setup. One of these, identified CVE-2024-9486, allows attackers to exploit default SSH credentials in Proxmox-based VM images, leading to root access and full system compromise. The other, CVE-2024-9594, requires access during the image build process and enables persistence of default credentials. To mitigate these risks, users should upgrade to Image Builder v0.1.38 or manually disable default builder accounts.