Skip to main content
See every side of every news story
Published loading...Updated

Chaos Mesh Critical GraphQL Flaws Enable RCE And Full Kubernetes Cluster Takeover - Cybernoz - Cybersecurity News

Summary by cybernoz.com
Sep 16, 2025Ravie LakshmananVulnerability / Cloud Security Cybersecurity researchers have disclosed multiple critical security vulnerabilities in Chaos Mesh that, if successfully exploited, could lead to cluster takeover in Kubernetes environments. “Attackers need only minimal in-cluster network access to exploit these vulnerabilities, execute the platform’s fault injections (such as shutting down pods or disrupting network communications), a…
DisclaimerThis story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.

6 Articles

The JFrog Security Research team has identified and exposed several critical vulnerabilities in Chaos-Mesh, a widely used testing platform in Kubernetes environments. The vulnerabilities have been summarized under the name "Chaotic Deputy" (CVE-2025-59358, CVE-2025-59359, CVE-2025-59360 and CVE-2025-59361), with the last three having a CVSS rating of 9.8 each. They allow attackers with access within the cluster, complete control over the environ…

Read Full Article

JFrog security researchers discover four vulnerabilities in the popular testing platform – three of them with CVSS score 9.8. An immediate update to version 2.7.3 is highly recommended. JFrog's security research team has discovered four critical vulnerabilities in Chaos Mesh, a widely used testing platform for Kubernetes environments. The vulnerabilities summarized under the name "Chaotic Deputy" (CVE-2025-59358, CVE-2025-59359, CVE-2025-59360 a…

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • There is no tracked Bias information for the sources covering this story.

Factuality 

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

The Hacker News broke the news in on Tuesday, September 16, 2025.
Sources are mostly out of (0)

Similar News Topics

News
For You
Search
BlindspotLocal