← Back to browse · API

CVE-2025-59359

Severity
CRITICAL
CVSS
9.8
EPSS
0.02926
Risk score
40.22
CISA KEV
No
PoC
Yes
Published
2025-09-15
Modified
2025-09-15
First seen
2026-08-07
Aliases
EUVD-2025-29176, GHSA-369H-6J28-WWCG
Products
linux, suse
Sources
packetstorm e760ebd193aaec6c0d4acb9c|CVE-2025-59359
euvd EUVD-2025-29176

Description

The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.

References