The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
References
Link | Resource |
---|---|
https://github.com/chaos-mesh/chaos-mesh/pull/4702 | Issue Tracking Patch |
https://jfrog.com/blog/chaotic-deputy-critical-vulnerabilities-in-chaos-mesh-lead-to-kubernetes-cluster-takeover | Exploit Third Party Advisory |
Configurations
History
14 Oct 2025, 14:43
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:chaos-mesh:chaos_mesh:*:*:*:*:*:*:*:* | |
First Time |
Chaos-mesh chaos Mesh
Chaos-mesh |
|
References | () https://github.com/chaos-mesh/chaos-mesh/pull/4702 - Issue Tracking, Patch | |
References | () https://jfrog.com/blog/chaotic-deputy-critical-vulnerabilities-in-chaos-mesh-lead-to-kubernetes-cluster-takeover - Exploit, Third Party Advisory |
15 Sep 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-15 12:15
Updated : 2025-10-14 14:43
NVD link : CVE-2025-59360
Mitre link : CVE-2025-59360
CVE.ORG link : CVE-2025-59360
JSON object : View
Products Affected
chaos-mesh
- chaos_mesh
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')