Executive brief
mcp-server-kubernetes is a tool used to manage Kubernetes clusters through AI-driven interfaces. A security flaw allowed users to bypass configured safety restrictions, such as 'read-only' modes, to perform destructive actions like deleting resources or executing commands in containers. This could lead to unauthorized cluster-wide changes or data loss if an authenticated user or AI agent ignores the intended access limits.
Technical details
An authorization bypass exists in mcp-server-kubernetes due to 'cosmetic' access control enforcement. While the server filters available tools during the discovery phase (tools/list) based on environment variables like ALLOWED_TOOLS or ALLOW_ONLY_READONLY_TOOLS, it fails to validate these restrictions during the execution phase (tools/call). An attacker with network access and valid authentication (MCP_AUTH_TOKEN) can directly invoke sensitive tools such as 'kubectl_delete' or 'exec_in_pod' by name, even if they are hidden from the tool list. This vulnerability is rooted in src/index.ts where the CallToolRequestSchema handler lacks the filtering logic present in the ListToolsRequestSchema handler. The issue is resolved in version 3.6.0.
Affected products
- Flux159 mcp-server-kubernetes < 3.6.0
Timeline
- 2026-05-14: patched: Version 3.6.0 released
- 2026-05-17: advisory: GitHub Security Advisory published
- 2026-06-11: disclosed: CVE-2026-46519 published to NVD