A critical security vulnerability has been identified in enterprise bridge implementations of the Model Context Protocol (MCP) for Kubernetes. Cataloged as CVE-2026-61459 with a CVSS v3.1 base score of 9.6, the vulnerability allows remote attackers who interact with AI-driven DevOps assistants to execute arbitrary tool argument injections. Exploitation enables adversaries to bypass Role-Based Access Control (RBAC), dump namespace secrets, and extract cluster administrative service account tokens.

The Rise of Model Context Protocol (MCP) in DevOps

The Model Context Protocol (MCP) has rapidly become the standard open protocol connecting large language models with development environments, databases, and container orchestrators. In DevOps workflows, MCP Kubernetes servers allow AI coding assistants (such as Claude Desktop, Cursor, or internal Slack bots) to query pod status, inspect deployments, and diagnose cluster alerts on behalf of developers.

When an AI model decides to invoke a tool—such as get_pod_logs(namespace, pod_name)—the MCP server receives a structured JSON-RPC message and translates the fields into an underlying CLI command or client-go API call.

Root Cause Analysis: Vulnerable CLI Argument Concatenation (CWE-88)

CVE-2026-61459 originates in the command construction logic of popular MCP Kubernetes bridge implementations (including versions prior to v0.8.4). Rather than using the official Kubernetes Go client library (client-go) with parameterized API calls, the server constructed shell arguments using unescaped string formatting:

// Vulnerable MCP Server Command Construction (Go)
func (s *K8sServer) HandleGetLogs(ctx context.Context, args LogArgs) (string, error) {
    // VULNERABLE: Direct string formatting into CLI arguments
    cmd := exec.Command("kubectl", "logs", args.PodName, "-n", args.Namespace)
    output, err := cmd.CombinedOutput()
    return string(output), err
}

Because the JSON schema for args.PodName permitted free-form string inputs without strict character whitelisting, an attacker interacting with an AI assistant can craft an indirect prompt injection that manipulates the model into emitting CLI flags inside the parameter:

# Attacker-Controlled JSON-RPC Tool Call Payload
{
  "jsonrpc": "2.0",
  "method": "tools/call",
  "params": {
    "name": "get_pod_logs",
    "arguments": {
      "namespace": "kube-system",
      "pod_name": "coredns-5556 --raw=/api/v1/namespaces/kube-system/secrets"
    }
  }
}

When kubectl parses the resulting argument array, the injected --raw flag overrides the logs subcommand, causing kubectl to perform an arbitrary REST request against the Kubernetes API server using the MCP server pod's own mounted service account token.

Exploitation Blast Radius

Attack Phase Attacker Input Underlying System Action Resulting Impact
Prompt Injection Malicious Git PR description or log snippet Triggers AI DevOps assistant to inspect logs Agent invokes MCP tool with poisoned arguments
Argument Injection pod_name: "test --raw=/api/v1/secrets" kubectl processes injected REST query flag Bypasses read-only tool scoping restrictions
Credential Theft Extraction of kube-system secret objects Dumps cloud provider IAM tokens & TLS keys Full cluster administrative takeover

Remediation & Hardening Steps

  1. Upgrade MCP Kubernetes Bridge Immediately: Deploy version 0.8.4 or higher, which completely eliminates direct exec.Command shell invocations in favor of typed k8s.io/client-go SDK calls.
  2. Enforce Regex Argument Constraints: In JSON schema definitions for all MCP tools, enforce strict POSIX and RFC 1123 naming constraints for all Kubernetes resource arguments:
    # Example JSON Schema Constraint for Pod Names
    pod_name:
      type: string
      pattern: "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$"
      maxLength: 253
  3. Least-Privilege Service Account Binding: Never bind cluster-admin roles to pods running MCP servers. Restrict the MCP ServiceAccount using granular RBAC roles that permit only read-only access to non-sensitive namespaces.
  4. Disable Raw CLI Flag Execution: Ensure container environments running MCP bridge daemons do not mount the kubectl binary or host Docker/containerd sockets.