CVE-2025-59377
LOWfeisky mcp-kubernetes-server <= 0.1.11 - OS Command Injection via /mcp/kubectl Endpoint
Title source: llmDescription
feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl because shell=True is used. NOTE: this is unrelated to mcp-server-kubernetes and CVE-2025-53355.
References (2)
Core 2
Scores
CVSS v3
3.7
EPSS
0.0003
EPSS Percentile
8.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-78
Status
published
Products (2)
feisky/mcp-kubernetes-server
< 0.1.11
pypi/mcp-kubernetes-server
0PyPI
Published
Sep 15, 2025
Tracked Since
Feb 18, 2026