{"id":"PYSEC-2026-371","summary":"Open Source Kubectl MCP Server vulnerable to arbitrary code execution via user interaction with crafted HTML page","details":"An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.","aliases":["CVE-2025-65719","GHSA-94gr-w3q5-rfqr"],"modified":"2026-07-01T20:22:55.271296Z","published":"2026-06-29T11:50:48.972414Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65719"},{"type":"PACKAGE","url":"https://github.com/rohitg00/kubectl-mcp-server"},{"type":"WEB","url":"https://www.ox.security/blog/cve-2025-65719-critical-rce-in-kubectl-mcp-server"},{"type":"WEB","url":"https://www.ox.security/blog/kubectl-mcp-server-remote-code-execution"},{"type":"PACKAGE","url":"https://pypi.org/project/kubectl-mcp-server"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-94gr-w3q5-rfqr"}],"affected":[{"package":{"name":"kubectl-mcp-server","ecosystem":"PyPI","purl":"pkg:pypi/kubectl-mcp-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.0"}]}],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/kubectl-mcp-server/PYSEC-2026-371.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}