PT-2026-25814 · Undefined · Undefined

Published

2026-03-16

·

Updated

2026-03-18

·

CVE-2025-69902

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kubectl-mcp-server version 1.2.0
Description A command injection issue exists in the minimal wrapper.py component of the software. Attackers can execute arbitrary commands by injecting shell metacharacters. The vulnerable component is minimal wrapper.py.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the minimal wrapper.py component to minimize the risk of exploitation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-69902

Affected Products

Undefined