MCPA-2025-0007
highrce-vectors
mcp-server-kubernetes command injection in several kubectl tools (CVE-2025-53355)
mcp-server-kubernetes before 2.5.0 builds kubectl command lines from unvalidated tool input and executes them with `child_process.execSync`, enabling shell metacharacter injection in tools such as `kubectl_scale`, `kubectl_patch`, and `explain_resource`. Indirect prompt injection via pod logs can chain into arbitrary command execution on the host running the server.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | mcp-server-kubernetes | >= 0, < 2.5.0 |
Identifiers
CVE-2025-53355GHSA-gjv4-ghm7-q58qCWE-78
References
- advisory https://github.com/Flux159/mcp-server-kubernetes/security/advisories/GHSA-gjv4-ghm7-q58q
- advisory https://github.com/advisories/GHSA-gjv4-ghm7-q58q
- advisory https://nvd.nist.gov/vuln/detail/CVE-2025-53355
Timeline
- Published: 2025-07-08