CVE-2025-65719Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-12: 2PoC Mentioned / Linked · 2026-05-12: 1Technical Details · 2026-05-12: 205-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets5 URLs
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - kubectl-mcp-server Remote Code Execution (CVE-2025-65719) A critical command injection vulnerability in kubectl-mcp-server allows unauthenticated attackers to execute arbitrary system commands (RCE). By injecting shell metacharacters into unsanitized input fields, an attacker can gain full control over the underlying host and potentially compromise the entire Kubernetes cluster. 👉 Affected: kubectl-mcp-server < 1.2.1

    Post summary

    The text announces a critical RCE vulnerability in kubectl-mcp-server, providing technical details and affected versions, with no PoC, exploit code, patch, or evidence of active exploitation.

    01031872
    187 followersView on X
  • Moshe Siman Tov Bustan@MosheTov
    Disclosure

    🚨 NEW Critical MCP Flaws 🚨 We discovered 3 new vulnerabilities in MCPs CVE-2025-65719 - ArchonOS CORS bypass exploit CVE-2025-69443 - kubectl-mcp-server Unauthenticated RCE Won't Fix - MarkItDown MCP - LPE via POST request The Archon OS CORS bypass allows any website to communicate with Archon and cross web to local boundaries to extract sensitive information and even control the Archon OS itself! (Check the POC it's pretty amazing - https://www.youtube.com/watch?v=t5GBb6-AScE) The kubectl-mcp-server vulnerability allows an attacker to execute commands on the kubectl-mcp-server by simply opening a malicious website. Click a link? -> command exec. BOOM. We published a LPE in MarkItDown MCP which won't be fixed, enabling a local attacker to reach files via POST requests when MarkItDown MCP is running on the machine. If you want to read more -> Main article: https://www.ox.security/blog/new-mcp-security-flaws-kubectl-mcp-server-archon-os-and-markitdown-vulnerabilities/ CVE-2025-69443 - Archon OS: https://www.ox.security/blog/cve-2025-69443-archon-os-vulnerable-to-unauthenticated-web-to-client-attack/ CVE-2025-65719 - kubectl-mcp-server: https://www.ox.security/blog/cve-2025-65719-critical-rce-in-kubectl-mcp-server/ MarkItDown MCP: https://www.ox.security/blog/markitdown-mcp-exposes-developer-machines-to-file-theft/

    Post summary

    New critical vulnerabilities were announced in MCPs with associated PoCs and detailed blog posts, though no active exploitation or patch details are provided.

    010201.0K
    884 followersView on X

Explore more