CVE-2025-59359: OS command injection in Chaos Mesh via the cleanTcs mutation
The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59359?
CVE-2025-59359 is classified as a critical vulnerability due to its potential for remote code execution.
How does CVE-2025-59359 affect the Chaos Controller Manager?
CVE-2025-59359 allows unauthenticated in-cluster attackers to execute arbitrary OS commands on the Chaos Controller Manager.
How can I mitigate CVE-2025-59359?
To mitigate CVE-2025-59359, update the Chaos Controller Manager to the latest version that addresses this vulnerability.
Is CVE-2025-59359 related to any other vulnerabilities?
Yes, CVE-2025-59359 is related to CVE-2025-59358, which enhances its exploitability for remote code execution.
What should I do if my system is vulnerable to CVE-2025-59359?
If your system is vulnerable to CVE-2025-59359, immediately apply security patches and review access controls to limit exposure.