PT-2025-37489 · Feiskyer · Mcp-Server-Kubernetes

William31212

·

Published

2025-09-15

·

Updated

2025-09-15

·

CVE-2025-59377

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions feiskyer mcp-kubernetes-server versions through 0.1.11
Description feiskyer mcp-kubernetes-server is susceptible to an OS command injection issue. This occurs through the /mcp/kubectl API endpoint, even when the system is in read-only mode, due to the use of shell=True.
Recommendations Update feiskyer mcp-kubernetes-server to a version beyond 0.1.11.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-59377
GHSA-4HQQ-7Q79-932P

Affected Products

Mcp-Server-Kubernetes