Vulnerability Management, Cloud Security

Total Kubernetes cluster hijacking likely with severe Chaos Mesh flaws

Adobe Stock

Open-source cloud-native Chaos Engineering platform Chaos Mesh was discovered to be impacted by four serious vulnerabilities collectively dubbed "Chaotic Deputy", which could be leveraged to facilitate complete Kubernetes cluster takeovers, according to The Hacker News.

Initial access to the targeted cluster's network could allow threat actors to harness the Chaos Controller Manager flaws, tracked from CVE-2025-59358 to CVE-2025-59361 which arose from inadequate authentication within its GraphQL server to enable arbitrary command execution, cluster compromise, data exfiltration, service disruptions, and lateral movement, a report from JFrog researchers showed.

All of the Chaos Mesh issues have already been resolved in an update released late last month.

"Platforms such as Chaos Mesh give, by design, complete control of the Kubernetes cluster to the platform. This flexibility can become a critical risk when vulnerabilities such as Chaotic Deputy are discovered," said JFrog Vice President of Security Research Shachar Menashe.

An In-Depth Guide to Cloud Security

Get essential knowledge and practical strategies to fortify your cloud security.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds