{"id":"GHSA-4hqq-7q79-932p","summary":"mcp-kubernetes-server has an OS Command Injection vulnerability","details":"`feiskyer/mcp-kubernetes-server` through **0.1.11** allows **OS command injection** via the `/mcp/kubectl` endpoint. The handler constructs a shell command with user-supplied arguments and executes it with `subprocess` using `shell=True`, enabling injection through shell metacharacters (e.g., `;`, `&&`, `$()`), even when the server is running in **read-only** mode.\n\nA remote, unauthenticated attacker can execute arbitrary OS commands on the host, resulting in full compromise of confidentiality, integrity, and availability.\n\nThis issue is **distinct from** `mcp-server-kubernetes` and from **CVE-2025-53355**.","aliases":["CVE-2025-59377","PYSEC-2026-409"],"modified":"2026-06-29T12:26:29.474889023Z","published":"2025-09-15T15:31:24Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-09-15T21:38:22Z","nvd_published_at":"2025-09-15T14:15:44Z","cwe_ids":["CWE-78"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59377"},{"type":"PACKAGE","url":"https://github.com/feiskyer/mcp-kubernetes-server"},{"type":"WEB","url":"https://github.com/feiskyer/mcp-kubernetes-server/blob/78957b6c1a3982080cf6fcaac6f6e9014116a71c/src/mcp_kubernetes_server/command.py#L38"},{"type":"WEB","url":"https://github.com/william31212/CVE-Requests-1896609"},{"type":"WEB","url":"https://www.tenable.com/cve/CVE-2025-59377"}],"affected":[{"package":{"name":"mcp-kubernetes-server","ecosystem":"PyPI","purl":"pkg:pypi/mcp-kubernetes-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.1.11"}]}],"versions":["0.1.0","0.1.1","0.1.10","0.1.11","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-4hqq-7q79-932p/GHSA-4hqq-7q79-932p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}