A AegiFlow
CRITICALCVSS 9.3EPSS 1.5%

CVE-2026-61459

mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials

Published
2026-07-10
Modified
2026-08-12
EPSS percentile
72%
Aliases
GHSA-wmg3-h8mf-wgvr
Sources
github-advisory

Summary

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPImcp-server-kubernetes3.9.0

Remediation: Upgrade to 3.9.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.