Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Four Chaos Mesh vulnerabilities disclosed on September 15, 2025, create a path from access inside a Kubernetes cluster to severe disruption—and, through command injection, potentially remote code execution across the cluster. The affected boundary stated in the advisories is Chaos Mesh versions before 2.7.3; operators are advised to upgrade to 2.7.3 or above. The described attack begins with in-cluster access, not a demonstrated internet-wide unauthenticated route into every deployment.

How the vulnerabilities fit together

The issues affect Chaos Controller Manager, a component of Chaos Mesh. One flaw exposes an unauthenticated GraphQL debugging server with a function that can kill processes in Kubernetes pods. Three related flaws allow operating-system command injection through specific mutations. Together, these weaknesses can turn an attacker’s foothold inside a cluster into a route to act on other pods.

JFrog’s report, which calls the chain “Chaotic Deputy,” describes an attacker with in-cluster access reaching the GraphQL server, using Chaos Mesh fault-injection functionality, and injecting commands through vulnerable mutations. JFrog gives stealing privileged service-account tokens as an example of possible impact. These are details from JFrog’s report, not a claim that every deployment is exposed to the same route or impact.

The access distinction matters: the GraphQL server is described as unauthenticated, but the attack scenario starts with access from within the Kubernetes cluster. The cited material does not establish that every affected deployment exposes the server to the public internet.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What each CVE does

CVE Issue Role and stated severity
CVE-2025-59358 Unauthenticated GraphQL debugging server in Chaos Controller Manager; includes a function that can kill arbitrary processes in Kubernetes pods. Can cause cluster-wide denial of service. GitLab Advisory Database lists CVSS 3.1 score 7.5, High, and CWE-306 (missing authentication for a critical function).
CVE-2025-59359 OS command injection in the cleanTcs mutation. NIST identifies CWE-78 and describes the issue in combination with CVE-2025-59358 as enabling unauthenticated in-cluster attackers to achieve remote code execution across the cluster. The NVD record shows a CVSS v3.1 vector but no NVD base-score assessment.
CVE-2025-59360 OS command injection in the killProcesses mutation. GitLab Advisory Database lists CVSS 3.1 score 9.8, Critical.
CVE-2025-59361 OS command injection in the cleanIptables mutation. GitLab Advisory Database lists CVSS 3.1 score 9.8, Critical.

The GitLab advisory records for these CVEs show a publication date of September 15, 2025. The scores above are attributed to the named advisory sources; NIST’s CVE-2025-59359 page does not provide an NVD base score.

Who is affected and what to do

The advisories identify versions of Chaos Mesh before 2.7.3 as affected and recommend upgrading to 2.7.3 or above. Check the version actually deployed in each relevant environment, including clusters where installations may differ. If it is below 2.7.3, prioritize upgrading in line with your organization’s change controls.

  1. Inventory deployments. Identify the Chaos Mesh version running in each cluster and note which environments contain versions before 2.7.3.
  2. Plan the upgrade. Use the project’s current release and deployment documentation for the applicable installation method. The advisory boundary establishes the target floor, but does not specify a deployment-specific upgrade procedure or establish which release is latest.
  3. Verify the resulting version. Confirm that the running installation is on 2.7.3 or above after the change, rather than relying only on a successful deployment command or package update.

The advisory records do not quantify how many deployments are affected. The available evidence also does not establish a single upgrade command that applies to every installation, so use the project’s current instructions for your deployment rather than applying a guessed command.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How vulnerability reports are handled

Chaos Mesh’s security and disclosure policy directs reports to the project security team. It describes a coordinated process in which confirmed vulnerabilities proceed through a draft GitHub advisory and private collaboration on a repair; public disclosure follows after fixes are merged into supported versions. This gives operators and researchers a project channel for reporting issues without treating an unpatched vulnerability as a public troubleshooting recipe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.