Database/AI/ML frameworks & serving
mcp-kubernetes-server: chained kubectl commands bypass the read-only --disable-write/--disable-delete guards
Impact
The server's read-only guards inspect only the first word of the command it was asked to run, so a chained command such as a harmless subcommand followed by a destructive one passes the check and executes in full. Operators deploy this MCP server precisely so an agent or LLM can inspect a cluster without being able to change it; the flag that promises that is not a boundary. On a GPU cluster the blast radius is whatever the server's kubeconfig can do - deleting training pods, removing the GPU operator's objects, dropping namespaces - driven by model output or by anyone who can reach the MCP endpoint. Prompt-injected content in cluster data is enough to turn an inspection agent into a delete.
Who can reach it
Whoever can submit tool calls to the MCP server: the agent runtime it is wired into, anyone on the network who can reach the endpoint if it is not fronted by auth, or an attacker who can get injected text in front of the model. No separate Kubernetes credential is needed - the server uses its own kubeconfig.
What to do
The record states the flaw through version 0.1.11 and names no fixed release, so treat the flags as advisory and enforce the boundary outside the process: give the server a Kubernetes service account with genuinely read-only RBAC, run it in its own namespace, and keep its endpoint behind authentication. Removing write and delete verbs from the RBAC role is the only control that actually holds; it takes effect without restarting anything beyond re-issuing the credential.
References
Related entries
- Hugging Face Transformers: ReDoS in the English number normalizer burns CPU on crafted inputCVE-2025-6051 · Hugging Face Transformers (EnglishNormalizer.normalize_numbers)Medium
- BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py): A model repository directory name flows unescapedCVE-2026-15035 · BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py)Medium
- JupyterHub: unauthenticated logins write unbounded usernames to the log, exhausting storageCVE-2026-54338 · JupyterHub form-based login authenticators (failed-login logging)Medium
- vLLM: malformed JSON to the OpenAI-compatible endpoints returns server paths and versionsCVE-2026-73555 · vLLM OpenAI-compatible API server (validation_exception_handler, sanitize_message)Medium
- vLLM: attacker-supplied structured-output regex pins a CPU core and stalls the engine pathCVE-2026-73556 · vLLM structured outputs, lm-format-enforcer backend (structured_outputs.regex)Medium
- vLLM: integer overflow in the activation CUDA kernel leaks another batched request's outputCVE-2026-73558 · vLLM CUDA activation kernels (act_and_mul_kernel, activation_kernels.cu)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.