id: PYSEC-2026-3685 published: "2026-08-19T11:56:25.076274Z" modified: "2026-08-19T12:16:28.926024Z" aliases: - CVE-2026-61459 - GHSA-wmg3-h8mf-wgvr summary: mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials details: MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise. affected: - package: name: mcp-server-kubernetes ecosystem: PyPI purl: pkg:pypi/mcp-server-kubernetes ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 3.9.0 versions: - 0.1.0 - 0.1.1 - 0.1.2 - 0.1.3 - 0.1.6 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2026-61459 - type: WEB url: https://github.com/Flux159/mcp-server-kubernetes/issues/328 - type: WEB url: https://github.com/Flux159/mcp-server-kubernetes/pull/329 - type: WEB url: https://github.com/Flux159/mcp-server-kubernetes/commit/d7890f50a4567bf5d9842541ba6f41e180227f9a - type: PACKAGE url: https://github.com/Flux159/mcp-server-kubernetes - type: WEB url: https://github.com/Flux159/mcp-server-kubernetes/releases/tag/3.9.0 - type: WEB url: https://www.vulncheck.com/advisories/mcp-server-kubernetes-argument-injection-via-kubectl-structured-tools - type: PACKAGE url: https://pypi.org/project/mcp-server-kubernetes - type: ADVISORY url: https://github.com/advisories/GHSA-wmg3-h8mf-wgvr severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - type: CVSS_V4 score: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N