PT-2026-57272 · Unknown · Mcp-Server-Kubernetes
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MCP Server Kubernetes versions prior to 3.9.0
Description
An argument injection issue exists in the structured tools
kubectl get(), kubectl describe(), and kubectl delete(). Improper input validation and argument parsing allow the resourceType and name parameters to bypass the assertNoDangerousFlags security check when they start with leading dashes. This allows an attacker to inject the --server flag, redirecting commands to a malicious API server. Consequently, the operator's bearer token can be transmitted externally, potentially leading to full compromise of the Kubernetes cluster.Recommendations
Update MCP Server Kubernetes to version 3.9.0.
Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Server-Kubernetes