The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
References
Configurations
No configuration.
History
15 Sep 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-15 12:15
Updated : 2025-09-15 15:21
NVD link : CVE-2025-59359
Mitre link : CVE-2025-59359
CVE.ORG link : CVE-2025-59359
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')