CVE-2025-59360
15.09.2025, 12:15
The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
| Vendor | Product | Version | 
|---|---|---|
| chaos-mesh | chaos_mesh | 𝑥 < 2.7.3 | 
𝑥
= Vulnerable software versions