PT-2025-37475 · Unknown · Chaos Controller Manager

Published

2025-09-15

·

Updated

2025-09-22

·

CVE-2025-59360

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chaos Controller Manager (affected versions not specified)
Description The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. This allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-59360
GHSA-XV9F-728H-9JGV
GO-2025-3954
OPENSUSE-SU-2025:15564-1
SUSE-SU-2025:03289-1

Affected Products

Chaos Controller Manager