mcp-server-kubernetes
MCP server for interacting with Kubernetes clusters via kubectl
Installing this server brings 403 third-party packages inside your agent's trust boundary (12 direct). This is attack surface, not a vulnerability count — it does not affect the grade above.
1 package in this tree runs a script at install time.
Findings (5)
- HIGH
VULN_KNOWN— GHSA-4xqg-gf5c-ghwq: MCP Server Kubernetes has an Argument Injection in port_forward tool via space-splitting. See https://osv.dev/vulnerability/GHSA-4xqg-gf5c-ghwq - MED
VULN_KNOWN— GHSA-6mx4-4h42-r8vh: MCP Server Kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration. See https://osv.dev/vulnerability/GHSA-6mx4-4h42-r8vh - HIGH
VULN_KNOWN— GHSA-cr22-wjx7-2w6m: MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement. See https://osv.dev/vulnerability/GHSA-cr22-wjx7-2w6m - HIGH
VULN_KNOWN— GHSA-gjv4-ghm7-q58q: MCP Server Kubernetes vulnerable to command injection in several tools. See https://osv.dev/vulnerability/GHSA-gjv4-ghm7-q58q - MED
VULN_KNOWN— GHSA-wvxp-jp4w-w8wg: mcp-server-kubernetes has potential security issue in exec_in_pod tool. See https://osv.dev/vulnerability/GHSA-wvxp-jp4w-w8wg
Embed this badge
[](https://vulnrable.com/mcp/mcp-server-kubernetes/)
Automated registry-metadata scan; not a code audit. Findings come from npm metadata
published by the package owner and from public security advisories (OSV/GHSA) — not from our own
assessment of the code.
Grade scanned 2026-09-04 · package count resolved 2026-08-18.
A package fixed after that date will still show its earlier grade here.
Maintainer and think this is wrong or out of date? Get in touch — corrections are welcome.