MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulnerability exists in the mcp-server-kubernetes MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call to child_process.execSync, enabling an attacker to inject arbitrary system commands. Successful exploitation can lead to remote code execution under the server process's privileges. This vulnerability is fixed in 2.5.0.
Metrics
Affected Vendors & Products
References
History
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 08 Jul 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 08 Jul 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulnerability exists in the mcp-server-kubernetes MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call to child_process.execSync, enabling an attacker to inject arbitrary system commands. Successful exploitation can lead to remote code execution under the server process's privileges. This vulnerability is fixed in 2.5.0. | |
Title | mcp-server-kubernetes vulnerable to command injection in several tools | |
Weaknesses | CWE-77 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-08T19:49:34.966Z
Updated: 2025-07-09T13:31:37.609Z
Reserved: 2025-06-27T12:57:16.120Z
Link: CVE-2025-53355

Updated: 2025-07-09T13:31:26.090Z

Status : Awaiting Analysis
Published: 2025-07-08T20:15:30.020
Modified: 2025-07-10T13:18:53.830
Link: CVE-2025-53355

No data.