The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/chaos-mesh/chaos-mesh(Go) | 0 | 2.7.3 | N/A |
CVSS Metrics