PT-2025-37474 · Unknown · Chaos Controller+1

Natan Nehorai

·

Published

2025-09-15

·

Updated

2025-09-22

·

CVE-2025-59359

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chaos Mesh (affected versions not specified)
Description A command injection flaw exists in Chaos Mesh’s cleanTcs mutation. This flaw allows unauthenticated in-cluster attackers to perform remote code execution across the cluster. The vulnerability is related to OS command injection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-59359
GHSA-369H-6J28-WWCG
GO-2025-3952
OPENSUSE-SU-2025:15564-1
SUSE-SU-2025:03289-1

Affected Products

Chaos Controller
Chaos-Mesh