Four Chaos Mesh vulnerabilities disclosed on September 15, 2025, create a path from access inside a Kubernetes cluster to severe disruption—and, through command injection, potentially remote code execution across the cluster. The affected boundary stated in the advisories is Chaos Mesh versions before 2.7.3; operators are advised to upgrade to 2.7.3 or above. The described attack begins with in-cluster access, not a demonstrated internet-wide unauthenticated route into every deployment.
How the vulnerabilities fit together
The issues affect Chaos Controller Manager, a component of Chaos Mesh. One flaw exposes an unauthenticated GraphQL debugging server with a function that can kill processes in Kubernetes pods. Three related flaws allow operating-system command injection through specific mutations. Together, these weaknesses can turn an attacker’s foothold inside a cluster into a route to act on other pods.
JFrog’s report, which calls the chain “Chaotic Deputy,” describes an attacker with in-cluster access reaching the GraphQL server, using Chaos Mesh fault-injection functionality, and injecting commands through vulnerable mutations. JFrog gives stealing privileged service-account tokens as an example of possible impact. These are details from JFrog’s report, not a claim that every deployment is exposed to the same route or impact.
The access distinction matters: the GraphQL server is described as unauthenticated, but the attack scenario starts with access from within the Kubernetes cluster. The cited material does not establish that every affected deployment exposes the server to the public internet.
#1 Best Overall
What each CVE does
| CVE | Issue | Role and stated severity |
|---|---|---|
| CVE-2025-59358 | Unauthenticated GraphQL debugging server in Chaos Controller Manager; includes a function that can kill arbitrary processes in Kubernetes pods. | Can cause cluster-wide denial of service. GitLab Advisory Database lists CVSS 3.1 score 7.5, High, and CWE-306 (missing authentication for a critical function). |
| CVE-2025-59359 | OS command injection in the cleanTcs mutation. |
NIST identifies CWE-78 and describes the issue in combination with CVE-2025-59358 as enabling unauthenticated in-cluster attackers to achieve remote code execution across the cluster. The NVD record shows a CVSS v3.1 vector but no NVD base-score assessment. |
| CVE-2025-59360 | OS command injection in the killProcesses mutation. |
GitLab Advisory Database lists CVSS 3.1 score 9.8, Critical. |
| CVE-2025-59361 | OS command injection in the cleanIptables mutation. |
GitLab Advisory Database lists CVSS 3.1 score 9.8, Critical. |
The GitLab advisory records for these CVEs show a publication date of September 15, 2025. The scores above are attributed to the named advisory sources; NIST’s CVE-2025-59359 page does not provide an NVD base score.
Who is affected and what to do
The advisories identify versions of Chaos Mesh before 2.7.3 as affected and recommend upgrading to 2.7.3 or above. Check the version actually deployed in each relevant environment, including clusters where installations may differ. If it is below 2.7.3, prioritize upgrading in line with your organization’s change controls.
- Inventory deployments. Identify the Chaos Mesh version running in each cluster and note which environments contain versions before 2.7.3.
- Plan the upgrade. Use the project’s current release and deployment documentation for the applicable installation method. The advisory boundary establishes the target floor, but does not specify a deployment-specific upgrade procedure or establish which release is latest.
- Verify the resulting version. Confirm that the running installation is on 2.7.3 or above after the change, rather than relying only on a successful deployment command or package update.
The advisory records do not quantify how many deployments are affected. The available evidence also does not establish a single upgrade command that applies to every installation, so use the project’s current instructions for your deployment rather than applying a guessed command.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How vulnerability reports are handled
Chaos Mesh’s security and disclosure policy directs reports to the project security team. It describes a coordinated process in which confirmed vulnerabilities proceed through a draft GitHub advisory and private collaboration on a repair; public disclosure follows after fixes are merged into supported versions. This gives operators and researchers a project channel for reporting issues without treating an unpatched vulnerability as a public troubleshooting recipe.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallQuick Recap
Best Value
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

