CVE-2026-46519
Description
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS, ALLOWED_TOOLS) documented as access controls for restricting which Kubernetes operations are available. These controls are enforced at the tool discovery layer (tools/list) but not at the execution layer (tools/call). Any client that knows a tool name can invoke it directly regardless of the configured restriction mode. The access control was effectively cosmetic. This issue has been patched in version 3.6.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mcp-server-kubernetesnpm | < 3.6.0 | 3.6.0 |
Affected products
3- Range: < 3.6.0
- osv-coords2 versionspkg:rpm/opensuse/atril&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/atril&distro=openSUSE%20Leap%2016.0
< 1.28.4-1.1+ 1 more
- (no CPE)range: < 1.28.4-1.1
- (no CPE)range: < 1.28.4-bp160.1.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.