CVE-2025-65719: Remote code execution in Kubectl MCP Server v1.1.1
A vulnerability in the open-source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim's system when the user interacts with a crafted HTML page. The flaw is tracked as CVE-2025-65719 and described as a critical RCE.
Disclosed 12 May 2026 · Record updated 13 September 2026
Impact
Attackers can achieve arbitrary code execution on systems running the affected MCP server if the user visits a crafted HTML page.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-65719
