Количество 2
Количество 2
CVE-2025-59376
feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g., it allows a "kubectl version; kubectl delete pod" command because the first word (i.e., "version") is not a write or delete operation.
GHSA-hjm5-xgj8-vwj6
mcp-kubernetes-server has a Command Injection vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-59376 feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g., it allows a "kubectl version; kubectl delete pod" command because the first word (i.e., "version") is not a write or delete operation. | CVSS3: 3.7 | 0% Низкий | 5 месяцев назад | |
GHSA-hjm5-xgj8-vwj6 mcp-kubernetes-server has a Command Injection vulnerability | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу