CVE-2026-61459
- EPSS 2.11%
- Veröffentlicht 10.07.2026 18:34:27
- Zuletzt bearbeitet 17.07.2026 12:27:18
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType an...
CVE-2026-39884
- EPSS 0.26%
- Veröffentlicht 14.04.2026 23:25:59
- Zuletzt bearbeitet 23.04.2026 17:22:46
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Versions 3.4.0 and prior contain an argument injection vulnerability in the port_forward tool in src/tools/port_forward.ts, where a kubectl command is constru...
CVE-2025-66404
- EPSS 1.5%
- Veröffentlicht 03.12.2025 20:40:11
- Zuletzt bearbeitet 16.12.2025 19:07:54
MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_pod tool of the mcp-server-kubernetes MCP Server. The tool accepts user-provided commands i...