← Back to browse · API

CVE-2025-59361

Severity
CRITICAL
CVSS
9.8
EPSS
0.03269
Risk score
40.34
CISA KEV
No
PoC
Yes
Published
2025-09-15
Modified
2025-09-15
First seen
2026-08-07
Aliases
EUVD-2025-29177, GHSA-2GCV-3QPF-C5QR
Products
linux, suse
Sources
euvd EUVD-2025-29177
packetstorm e760ebd193aaec6c0d4acb9c|CVE-2025-59361

Description

The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.

References