Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmg3-h8mf-wgvr

Опубликовано: 10 июл. 2026
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.

Пакеты

Наименование

mcp-server-kubernetes

pip
Затронутые версииВерсия исправления

< 3.9.0

3.9.0

EPSS

Процентиль: 80%
0.02105
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 месяца назад

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.

EPSS

Процентиль: 80%
0.02105
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-88