The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
https://www.infosecurity-magazine.com/news/cves-chaos-mesh-cluster-code/
https://www.darkreading.com/cyber-risk/critical-bugs-chaos-mesh-cluster-takeover
https://thehackernews.com/2025/09/chaos-mesh-critical-graphql-flaws.html