PT-2025-37476 · Unknown · Chaos Controller Manager

Natan Nehorai

·

Published

2025-09-15

·

Updated

2025-09-22

·

CVE-2025-59361

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chaos Controller Manager (affected versions not specified)
Description The cleanIptables mutation is susceptible to OS command injection. This allows unauthenticated in-cluster attackers to potentially execute remote code across the cluster. Attackers may gain root access on Kubernetes nodes through exploitation of this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-59361
GHSA-2GCV-3QPF-C5QR
GO-2025-3949
OPENSUSE-SU-2025:15564-1
SUSE-SU-2025:03289-1

Affected Products

Chaos Controller Manager