Логотип exploitDog
bind:CVE-2025-59376
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-59376

Количество 2

Количество 2

nvd логотип

CVE-2025-59376

5 месяцев назад

feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g., it allows a "kubectl version; kubectl delete pod" command because the first word (i.e., "version") is not a write or delete operation.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-hjm5-xgj8-vwj6

5 месяцев назад

mcp-kubernetes-server has a Command Injection vulnerability

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-59376

feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g., it allows a "kubectl version; kubectl delete pod" command because the first word (i.e., "version") is not a write or delete operation.

CVSS3: 3.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-hjm5-xgj8-vwj6

mcp-kubernetes-server has a Command Injection vulnerability

CVSS3: 5.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу