Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4996 articles · 189019 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-61459EXPLOITEDPATCHED
suyogs · mcp-server-kubernetes

MCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured Tools

Description

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.

Affected Products

VendorProductVersions
suyogsmcp-server-kubernetespip/mcp-server-kubernetes: < 3.9.0

References

  • https://github.com/Flux159/mcp-server-kubernetes/releases/tag/3.9.0(release-notes)
  • https://github.com/Flux159/mcp-server-kubernetes/issues/328(exploit, technical-description)
  • https://github.com/Flux159/mcp-server-kubernetes/pull/329(issue-tracking)
  • https://github.com/Flux159/mcp-server-kubernetes/commit/d7890f50a4567bf5d9842541ba6f41e180227f9a(patch)
  • https://www.vulncheck.com/advisories/mcp-server-kubernetes-argument-injection-via-kubectl-structured-tools(third-party-advisory)

Related News (2 articles)

Tier C
Exploit-DB1d ago
[remote] mcp-server-kubernetes 3.8.x - Argument Injection
→ No new info (linked only)
Tier C
VulDB33d ago
CVE-2026-61459 | Flux159 MCP Server Kubernetes up to 3.8.x Argument Parser resourceType/name argument injection
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
mcp-server-kubernetes@3.9.0
CWECWE-88
PublishedJul 10, 2026
Last enriched33d agov2
Trending Score66
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 10, 2026
Discovered by ZDM
Jul 10, 2026
Updated: description, affectedVersions, activelyExploited
Jul 10, 2026
Actively Exploited
Jul 14, 2026
Patch Available
Jul 14, 2026

Version History

v2
Last enriched 33d ago
v2Tier C33d ago

Updated description with new details, added affected versions up to 3.8.x, and marked the vulnerability as actively exploited.

descriptionaffectedVersionsactivelyExploited
via VulDB
v133d ago

Initial creation