CVE-2026-61459Disclosure(suyogs / mcp-server-kubernetes)

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch suyogs mcp-server-kubernetes systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp-server-kubernetes

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-07-10); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
mcp-server-kubernetes

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-07-10: 3Mentions · 2026-07-11: 2Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-07-11: 2Technical Details · 2026-07-10: 3Technical Details · 2026-07-11: 207-1007-11
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-103
Disclosure1General1Patch1
2026-07-112
Disclosure1Patch1
Full discourse5 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - kubectl argument injection via structured tools flag bypass (CVE-2026-61459) MCP Server Kubernetes before 3.9.0 is vulnerable to argument injection in its kubectl structured tools (kubectl_get, kubectl_describe, kubectl_delete) when handling resourceType and name inputs. The root cause is improper input validation/argument parsing that allows parameters beginning with dashes to bypass the assertNoDangerousFlags safeguard. An attacker who can invoke these tools can supply crafted values to inject the --server flag and redirect kubectl to an attacker-controlled Kubernetes API endpoint. Impact includes exfiltration of the operator’s bearer token and subsequent full Kubernetes cluster compromise (credential theft leading to total control). 👉 Affected: mcp-server-kubernetes < 3.9.0 | Upgrade to 3.9.0

    Post summary

    The post discloses that versions of MCP Server Kubernetes before 3.9.0 are vulnerable to kubectl argument injection via structured tools, which can redirect API calls and expose bearer tokens, and it recommends upgrading to version 3.9.0.

    00030185
    300 followersView on X
  • ThreatAft@ThreatAft
    Patch

    🚨 CRITICAL: CVE-2026-61459 — MCP Server Kubernetes CVSS 9.8. Argument injection via kubectl_get allows unauthenticated attackers to steal bearer tokens and take over Kubernetes clusters. Patch to 3.9.0 NOW. → http://threataft.com/articles/cve-2026-61459-mcp-server-kubernetes-argument-injection #cybersecurity #infosec #Kubernetes

    Post summary

    The post announces CVE-2026-61459, a critical Kubernetes argument‑injection flaw, and urges users to upgrade to patch 3.9.0 immediately.

    0001092
    34 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-61459 — CVSS 9.8/10 ██████████ MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get,... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/Xdry3fVqr3

    Post summary

    A critical argument injection CVE (CVE‑2026‑61459) affecting Kubernetes <=3.8 has been disclosed with an urgent patch issued; no exploit, PoC, or active exploitation claims are present.

    10000131
    65 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-61459 MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attack… https://www.cve.org/CVERecord?id=CVE-2026-61459 ----- Traducción: CVE-2026-61459 MCP… http://infoflow.cloud`

    Post summary

    The text announces an argument injection flaw in MCP Server Kubernetes (pre‑3.9.0) affecting specific kubectl tools, providing technical details but no PoC, exploit code, or patch information.

    0000047
    91 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-61459 MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attack… https://www.cve.org/CVERecord?id=CVE-2026-61459

    Post summary

    The text reports a new argument injection vulnerability in Kubernetes versions before 3.9.0, but provides no proof of concept, exploit code, active exploitation mention, or patch details.

    00000709
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsuyogsmcp-server-kubernetes-node.js-

Explore more