Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-61459: MCP Server Kubernetes: Argument Injection Risk in kubectl Tools
CVE-2026-61459
Summary
MCP Server Kubernetes versions before 3.9.0 have a security risk in certain tools (kubectl_get, kubectl_describe, kubectl_delete). This means an attacker could trick the system into sending sensitive information to an unauthorized server. To stay safe, update to version 3.9.0 or later.
Original title
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDange...
Original description
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-88
- https://github.com/Flux159/mcp-server-kubernetes/commit/d7890f50a4567bf5d9842541...
- https://github.com/Flux159/mcp-server-kubernetes/issues/328
- https://github.com/Flux159/mcp-server-kubernetes/pull/329
- https://github.com/Flux159/mcp-server-kubernetes/releases/tag/3.9.0
- https://www.vulncheck.com/advisories/mcp-server-kubernetes-argument-injection-vi...
Published: 10 Jul 2026 · Updated: 18 Jul 2026 · First seen: 10 Jul 2026