Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29178 | The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster. |
Github GHSA |
GHSA-xv9f-728h-9jgv | Chaos Controller Manager is vulnerable to OS command injection |
Tue, 14 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chaos-mesh chaos Mesh
|
|
| CPEs | cpe:2.3:a:chaos-mesh:chaos_mesh:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Chaos-mesh chaos Mesh
|
Wed, 17 Sep 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chaos-mesh
Chaos-mesh chaos-mesh |
|
| Vendors & Products |
Chaos-mesh
Chaos-mesh chaos-mesh |
Mon, 15 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Sep 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster. | |
| Title | OS command injection in Chaos Mesh via the killProcesses mutation | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: JFROG
Published:
Updated: 2025-09-15T20:34:59.504Z
Reserved: 2025-09-12T17:59:19.914Z
Link: CVE-2025-59360
Updated: 2025-09-15T20:34:54.481Z
Status : Analyzed
Published: 2025-09-15T12:15:33.790
Modified: 2025-10-14T14:43:35.363
Link: CVE-2025-59360
No data.
OpenCVE Enrichment
Updated: 2025-09-17T10:08:13Z
EUVD
Github GHSA