CVE-2025-59376

LOW

Feisky Mcp-kubernetes-server < 0.1.11 - Command Injection

Title source: rule

Description

feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g., it allows a "kubectl version; kubectl delete pod" command because the first word (i.e., "version") is not a write or delete operation.

Exploits (1)

nomisec WORKING POC 1 stars
by william31212 · poc
https://github.com/william31212/CVE-Requests-1896609

Scores

CVSS v3 3.7
EPSS 0.0001
EPSS Percentile 0.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-77 CWE-863
Status published
Products (2)
feisky/mcp-kubernetes-server < 0.1.11
pypi/mcp-kubernetes-server 0PyPI
Published Sep 15, 2025
Tracked Since Feb 18, 2026