Products: 1
    Vulnerabilities: 2
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    0
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-59376

    feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g., it allows a "kubectl version; kubectl delete pod" command because the first word (i.e., "version") is not a write or delete operation.

    Last Modified: Sep 20, 2025
    Published: Sep 15, 2025

    CVE-2025-59377

    feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl because shell=True is used. NOTE: this is unrelated to mcp-server-kubernetes and CVE-2025-53355.

    Last Modified: Sep 20, 2025
    Published: Sep 15, 2025
    Items Per Page
    Feisky Vulnerabilities & Security CVEs | CVE-DB