Chaos Mesh is a cloud-native chaos engineering and fault-injection platform designed for testing and validation of distributed systems and Kubernetes environments; its vulnerability footprint remains concentrated in this single, specialized product. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chaos Mesh over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59361CRITICAL The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers t | Sep 15, 2025 | 9.8 | 36 | NO | NO |
CVE-2025-59359CRITICAL The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to pe | Sep 15, 2025 | 9.8 | 36 | NO | NO |
CVE-2025-59360CRITICAL The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers t | Sep 15, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-59358HIGH The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary proce | Sep 15, 2025 | 7.5 | 29 | NO | NO |
CVE-2024-36538HIGH Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | Jul 24, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chaos Mesh.
Media articles that mention a CVE ID that affects a product developed by Chaos Mesh — matched by CVE ID, not by vendor name.