PT-2025-37475 · Unknown · Chaos Controller Manager

CVE-2025-59360

·

Published

2025-09-15

·

Updated

2026-07-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chaos Controller Manager (affected versions not specified)
Description The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. This allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59360
GHSA-XV9F-728H-9JGV
GO-2025-3954
OPENSUSE-SU-2025:15564-1
OPENSUSE-SU-2026:21483-1
SUSE-SU-2025:03289-1

Affected Products

Chaos Controller Manager