Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Argument injection in mcp-server-kubernetes port_forward tool (CVE-2026-39884)

Versions 3.4.0 and earlier of mcp-server-kubernetes, a Model Context Protocol server for Kubernetes cluster management, built a kubectl command by string concatenation and naive space-splitting in the port_forward tool, allowing attackers to inject arbitrary kubectl flags. This could expose internal Kubernetes services to the network (via --address=0.0.0.0) or target other namespaces, and could be triggered indirectly through prompt injection against connected AI agents; fixed in version 3.5.0.

Disclosed 15 April 2026 · Record updated 13 September 2026

Impact

Attackers could inject arbitrary kubectl flags to expose internal Kubernetes services to the network or target resources in other namespaces, exploitable indirectly via prompt injection against AI agents using the MCP server.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-39884