
🚨 CRITICAL - kubectl argument injection via structured tools flag bypass (CVE-2026-61459) MCP Server Kubernetes before 3.9.0 is vulnerable to argument injection in its kubectl structured tools (kubectl_get, kubectl_describe, kubectl_delete) when handling resourceType and name inputs. The root cause is improper input validation/argument parsing that allows parameters beginning with dashes to bypass the assertNoDangerousFlags safeguard. An attacker who can invoke these tools can supply crafted values to inject the --server flag and redirect kubectl to an attacker-controlled Kubernetes API endpoint. Impact includes exfiltration of the operator’s bearer token and subsequent full Kubernetes cluster compromise (credential theft leading to total control). 👉 Affected: mcp-server-kubernetes < 3.9.0 | Upgrade to 3.9.0
Post summary
The post discloses that versions of MCP Server Kubernetes before 3.9.0 are vulnerable to kubectl argument injection via structured tools, which can redirect API calls and expose bearer tokens, and it recommends upgrading to version 3.9.0.




