A high-severity flaw tracked as CVE-2026-61459 affects Flux159's mcp-server-kubernetes before version 3.9.0, allowing argument injection in the structured tools kubectl_get, kubectl_describe, and kubectl_delete. Attackers can supply resourceType or name values beginning with dashes to bypass the project's assertNoDangerousFlags check and inject flags such as --server, redirecting kubectl requests to an attacker-controlled Kubernetes API endpoint.
The redirection can cause the operator's bearer token to be transmitted externally and could lead to full Kubernetes cluster compromise. Flux159 addressed the issue in version 3.9.0 with a hardening patch that adds argv-wide validation through assertSafeArgv and a guarded execution wrapper, replacing direct command execution across affected kubectl and helm modules while also blocking dangerous kube-related flags that could alter API server or credential handling.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Public advisories described CVE-2026-61459 as an argument injection vulnerability in mcp-server-kubernetes structured tools including kubectl_get, kubectl_describe, and kubectl_delete. The disclosures explained that attackers could bypass the existing dangerous-flag check with leading-dash parameters and redirect kubectl to an attacker-controlled API server.
References state that the argument injection vulnerability affecting mcp-server-kubernetes versions before 3.9.0 was addressed in the 3.9.0 release. The flaw allowed attackers to abuse structured kubectl tools by passing leading-dash parameters such as --server to exfiltrate bearer tokens and potentially compromise a cluster.
A GitHub commit introduced argv-wide validation and a guarded execFileSync wrapper to block dangerous kubectl and helm flags, mitigating argument injection that could redirect connections to an attacker-controlled Kubernetes API server or substitute credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.