Impact
MCP Server Kubernetes before version 3.9.0 has an argument‑injection flaw in its structured tools (kubectl_get, kubectl_describe, kubectl_delete). By crafting the resourceType and name parameters with leading dashes, an attacker can bypass the internal assertNoDangerousFlags check and inject a --server flag. The injected flag redirects the kubectl command to an attacker‑controlled API server, causing the operator’s bearer token to be transmitted externally and enabling full compromise of the Kubernetes cluster.
Affected Systems
Flux159 MCP Server Kubernetes versions released prior to 3.9.0 are affected. The product is a Node.js‑based application that exposes the kubectl_* structured tools without proper validation.
Risk and Exploitability
The CVSS score of 9.3 marks the flaw as critical. Its EPSS score of less than 1 % indicates a low current exploitation probability, and it is not listed in the CISA KEV catalog. However, because the vulnerability can be exploited remotely by invoking the vulnerable tools, the risk remains high if the service is exposed to untrusted networks. An attacker can redirect commands, exfiltrate authentication tokens, and ultimately gain full cluster control.
OpenCVE Enrichment