CVE-2025-59361: OS command injection in Chaos Mesh via the cleanIptables mutation
Published Sep 15, 2025
·Updated
The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
Affected Software
2 affected componentsFixes available
go/github.com/chaos-mesh/chaos-mesh<2.7.3
2.7.3
chaos-mesh Chaos Mesh<2.7.3
Event History
Sep 15, 2025
CVE Published
via MITRE·11:41 AM
Data Sourced
via MITRE·11:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
Affected Software
Advisory Published
via GitHub·12:31 PM
Data Sourced
via GitHub·12:31 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59361?
CVE-2025-59361 is considered critical due to the potential for unauthenticated remote code execution.
2
How do I fix CVE-2025-59361?
To mitigate CVE-2025-59361, upgrade to version 2.7.3 or later of the Chaos Mesh software.
3
Who is affected by CVE-2025-59361?
CVE-2025-59361 affects users of Chaos Mesh prior to version 2.7.3 that run in cluster environments.
4
Can CVE-2025-59361 lead to additional vulnerabilities?
Yes, in conjunction with CVE-2025-59358, it allows remote code execution risks to escalate significantly.
5
What is the nature of the vulnerability in CVE-2025-59361?
CVE-2025-59361 involves OS command injection through the cleanIptables mutation, which can be exploited by attackers.