Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20689 | MCP Server Kubernetes vulnerable to command injection in several tools |
Github GHSA |
GHSA-gjv4-ghm7-q58q | MCP Server Kubernetes vulnerable to command injection in several tools |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 08 Jul 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulnerability exists in the mcp-server-kubernetes MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call to child_process.execSync, enabling an attacker to inject arbitrary system commands. Successful exploitation can lead to remote code execution under the server process's privileges. This vulnerability is fixed in 2.5.0. | |
| Title | mcp-server-kubernetes vulnerable to command injection in several tools | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-09T13:31:37.609Z
Reserved: 2025-06-27T12:57:16.120Z
Link: CVE-2025-53355
Updated: 2025-07-09T13:31:26.090Z
Status : Deferred
Published: 2025-07-08T20:15:30.020
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-53355
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA