CVE-2025-59377: Feisky Mcp-Kubernetes-Server
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl because shell=True is used. NOTE: this is unrelated to mcp-server-kubernetes and CVE-2025-53355.
Affected products
- Feisky Mcp-Kubernetes-Server: up to and including 0.1.11
Published 2025-09-15. Last modified 2026-06-17.