The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
https://www.securityweek.com/in-other-news-600k-hit-by-healthcare-breaches-major-shinyhunters-hacks-deepseeks-coding-bias/
https://www.infosecurity-magazine.com/news/cves-chaos-mesh-cluster-code/
https://www.darkreading.com/cyber-risk/critical-bugs-chaos-mesh-cluster-takeover
https://thehackernews.com/2025/09/chaos-mesh-critical-graphql-flaws.html
https://jfrog.com/blog/chaotic-deputy-critical-vulnerabilities-in-chaos-mesh-lead-to-kubernetes-cluster-takeover
https://github.com/chaos-mesh/chaos-mesh/pull/4702
Source: Mitre, NVD
Published: 2025-09-15
Updated: 2025-10-14
Named Vulnerability: Chaotic Deputy
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.00483