References https://jfrog.com/blog/chaotic-deputy-critical-vulnerabilities-in-chaos-mesh-lead-to-kubernetes-cluster-takeover/ https://thehackernews.com/2025/09/chaos-mesh-critical-graphql-flaws.html https://www.ithome.com.tw/news/171238 https://hoeasys.com/blogs/CyberSecurityNews/2025-09/0918-Unmasking--Chaotic-Deputy---The-Chaos-Mesh-Vulnerability-That-Can-Cripple-Kubernetes-Clusters.html https://www.knowsafe.com/ti/info/0/987073 https://gbhackers.com/chaos-mesh-critical-vulnerabilities/ https://www.infosecurity-magazine.com/news/cves-chaos-mesh-cluster-code/ https://www.darkreading.com/cyber-risk/critical-bugs-chaos-mesh-cluster-takeover https://chaos-mesh.org/docs/manage-user-permissions/ https://github.com/chaos-mesh/chaos-mesh/blob/master/SECURITY.md
Related VulnerabilitiesChaos Mesh killProcesses 未授权 命令注入漏洞Chaos Mesh cleanIptables 未授权 命令注入漏洞Chaos Mesh 未授权 命令注入漏洞(CVE-2025-8791)LitmusChaos Litmus role参数不恰当授权漏洞(CVE-2025-8792)LitmusChaos Litmus服务端安全控制绕过漏洞(CVE-2025-8794)LitmusChaos Litmus授权绕过漏洞(CVE-2025-8793)LitmusChaos Litmus项目ID参数不当控制漏洞PoCCVE-2023-47105: Chaosblade < 1.7.4 - Remote Code ExecutionPoCCVE-2024-31839: CHAOS 5.0.1 'sendCommandHandler' - Cross-Site ScriptingChaos RAT 远程代码执行漏洞