feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl because shell=True is used. NOTE: this is unrelated to mcp-server-kubernetes and CVE-2025-53355.
{ "versions": [ { "introduced": "0" }, { "last_affected": "0.1.11" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59377.json"