CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-61459

Critical · CVSS 9.8

mcp-server-kubernetes — argument injection via kubectl structured tools (CWE-88)

CVSS
9.8
nvd
EPSS
0.42%
34th pct
KEV
No
Class
oss containerizable
CWE-88

Description

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.

Search profile — drives PoC discovery

Symbols kubectl_getkubectl_describekubectl_deleteassertNoDangerousFlagsresourceType--serverbearer token
Keywords CVE-2026-61459mcp-server-kubernetesargument injectionkubectlassertNoDangerousFlagskubectl_getkubectl_describekubectl_delete--server flag injectionbearer token exfiltrationFlux159
Versions: < 3.9.0

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z