Chaotic Deputy: Critical vulnerabilities in Chaos Mesh lead to Kubernetes cluster takeover
jfrog.com | blog | #cloud | #rce | #kubernetes | #jfrog | #vulnerability-disclosure | #cloud-native | #chaos-mesh | #cve-2025-59358
Summary
JFrog discloses 'Chaotic Deputy': four Chaos Mesh CVEs, three rated CVSS 9.8, letting in-cluster attackers — even in unprivileged pods — run code on any pod; fixed in 2.7.3.
- Published
- Collected
Skip to content