← Back to browse · API

CVE-2025-69902

Severity
CRITICAL
CVSS
9.8
EPSS
0.02057
Risk score
39.92
CISA KEV
No
PoC
No
Published
2026-03-16
Modified
2026-03-17
First seen
2026-08-07
Aliases
EUVD-2025-208773, GHSA-Q2W8-W8PJ-C9WH
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-208773

Description

A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters.

References