Vulnerabilities (CVE)

Filtered by vendor Suyogs
Filtered by product Mcp-server-kubernetes
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-66404 1 Suyogs 1 Mcp-server-kubernetes 2025-12-16 N/A 6.4 MEDIUM
MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_pod tool of the mcp-server-kubernetes MCP Server. The tool accepts user-provided commands in both array and string formats. When a string format is provided, it is passed directly to shell interpretation (sh -c) without input validation, allowing shell metacharacters to be interpreted. This vulnerability can be exploited through direct com ...

Show More