Description

feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g., it allows a "kubectl version; kubectl delete pod" command because the first word (i.e., "version") is not a write or delete operation.

INFO

Published Date :

2025-09-15T00:00:00.000Z

Last Modified :

2025-09-15T15:10:46.266Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-59376 vulnerability.

Vendors Products
Feisky
  • Mcp-kubernetes-server
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact