CVE-2025-59360: OS command injection in Chaos Mesh via the killProcesses mutation
The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59360?
CVE-2025-59360 is classified as a critical vulnerability due to its potential for allowing unauthenticated remote code execution.
How do I fix CVE-2025-59360?
To mitigate CVE-2025-59360, update the Chaos Controller Manager to the latest patched version.
Who is affected by CVE-2025-59360?
CVE-2025-59360 affects all instances of the Chaos Mesh Chaos Controller Manager that are deployed in a Kubernetes environment.
What type of attack does CVE-2025-59360 allow?
CVE-2025-59360 allows unauthenticated in-cluster attackers to execute arbitrary commands, leading to potential remote code execution.
Is CVE-2025-59360 related to other vulnerabilities?
Yes, CVE-2025-59360 is related to CVE-2025-59358, which together enable a more severe attack vector.