PYSEC-2026-1619
mcp-kubernetes-server has a Command Injection vulnerability
Details
`mcp-kubernetes-server` does not correctly enforce the `--disable-write` / `--disable-delete` protections when commands are chained. The server only inspects the first token to decide whether an operation is write/delete, which allows a read-like command to be followed by a write action using shell metacharacters (e.g., `kubectl version; kubectl delete pod <name>`). A remote attacker who can invoke the server may therefore bypass the intended write/delete restrictions and perform state-changing operations against the Kubernetes cluster.
**Affected versions:** through `0.1.11` (no patched release available as of now).
**Mitigations:** - Run with `--disable-kubectl` and/or `--disable-helm` to fully block those execution paths. - Put the server behind an allow-list proxy restricting allowed subcommands.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for mcp-kubernetes-server (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-59376[ADVISORY]
- https://github.com/feiskyer/mcp-kubernetes-server[PACKAGE]
- https://github.com/feiskyer/mcp-kubernetes-server/blob/78957b6c1a3982080cf6fcaac6f6e9014116a71c/src/mcp_kubernetes_server/main.py#L106-L137[WEB]
- https://github.com/william31212/CVE-Requests-1896609[WEB]
- https://pypi.org/project/mcp-kubernetes-server[PACKAGE]
- https://github.com/advisories/GHSA-hjm5-xgj8-vwj6[ADVISORY]