VDB
Sign up
CRITICAL9.8

PYSEC-2026-409

mcp-kubernetes-server has an OS Command Injection vulnerability

Details

`feiskyer/mcp-kubernetes-server` through **0.1.11** allows **OS command injection** via the `/mcp/kubectl` endpoint. The handler constructs a shell command with user-supplied arguments and executes it with `subprocess` using `shell=True`, enabling injection through shell metacharacters (e.g., `;`, `&&`, `$()`), even when the server is running in **read-only** mode.

A remote, unauthenticated attacker can execute arbitrary OS commands on the host, resulting in full compromise of confidentiality, integrity, and availability.

This issue is **distinct from** `mcp-server-kubernetes` and from **CVE-2025-53355**.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/mcp-kubernetes-server
Introduced in: 0

No fixed version published yet for mcp-kubernetes-server (pip). Pin to a known-safe version or switch to an alternative.

References