PYSEC-2026-371

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/kubectl-mcp-server/PYSEC-2026-371.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-371
Aliases
Published
2026-06-29T11:50:48Z
Modified
2026-07-01T20:22:55Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Open Source Kubectl MCP Server vulnerable to arbitrary code execution via user interaction with crafted HTML page
Details

An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.

References

Affected packages

PyPI / kubectl-mcp-server

Package

Name
kubectl-mcp-server
View open source insights on deps.dev
Purl
pkg:pypi/kubectl-mcp-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/kubectl-mcp-server/PYSEC-2026-371.yaml"