Command Injection Vulnerability in MCP Server for Kubernetes by False257
CVE-2025-53355
What is CVE-2025-53355?
A critical command injection vulnerability exists in the MCP Server Kubernetes, which facilitates connections to Kubernetes clusters for management purposes. Due to improper sanitization of input parameters used in the child_process.execSync call, this vulnerability allows attackers to inject arbitrary system commands. Exploitation of this flaw can lead to remote code execution with the privileges of the server process. This issue has been addressed in version 2.5.0, emphasizing the importance of updating to mitigate potential security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
mcp-server-kubernetes < 2.5.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
