Description
MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server structure for direct docker:// references and catalog snapshot imports in pkg/oci/self_contained.go and pkg/workingset/workingset.go. Runtime-shaping fields including Volumes, User, and ExtraHosts were then appended to the docker run argument vector without an origin allowlist, allowing a malicious image author to request host filesystem or Docker socket mounts and UID 0 execution when a victim selected or pulled the image. This container-creation-time boundary bypass can execute arbitrary code on the host and is not prevented by no-new-privileges because no in-container privilege escalation is required. This issue is fixed in version 0.42.2.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Docker MCP Gateway allows deployment of MCP servers, and from release 0.21.0 to 0.42.2 it YAML‑unmarshalled the attacker‑controlled io.docker.server.metadata OCI image label into the catalog.Server structure used for docker:// references and catalog snapshot imports. Runtime‑shaping fields such as Volumes, User, and ExtraHosts were appended directly to the docker run argument vector without any origin allowlist. A malicious image author can therefore request host filesystem or Docker socket mounts and launch a container with UID 0, enabling the execution of arbitrary code on the host at container start time. This container‑creation‑time boundary bypass is not mitigated by no‑new‑privileges because no in‑container privilege escalation is required. The vulnerability is fixed in version 0.42.2 and is classified as CWE‑88.

Affected Systems

All deployments of Docker MCP Gateway running any release from version 0.21.0 through 0.42.1 are vulnerable. The flaw was addressed with the release of 0.42.2; any instance that has not been updated to that version remains susceptible.

Risk and Exploitability

The CVSS base score of 8.7 signals high severity, while the EPSS value of less than 1 % indicates a very low, but not zero, probability of exploitation. No special privileges are needed beyond pulling a malicious image; an attacker can achieve host‑level code execution simply by installing or pulling the compromised OCI image. This vulnerability is not listed in CISA’s KEV catalog, yet the combination of high impact and easy exploitation path warrants urgent attention.

Generated by OpenCVE AI on September 20, 2026 at 16:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Docker MCP Gateway to version 0.42.2 to eliminate the unchecked injection path.
  • If an upgrade is not immediately possible, restrict image pulls to trusted registries and audit image labels for dangerous fields such as Volumes, User, and ExtraHosts before deployment.
  • Monitor container launch logs for unexpected host mounts, privileged flags, or UID 0 configurations, and enforce ingress policies that deny such insecure settings unless explicitly approved.

Generated by OpenCVE AI on September 20, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-r2xf-7jw5-pjg6 Docker MCP Gateway: Argument injection via OCI image label YAML
History

Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Docker
Docker mcp Gateway
Vendors & Products Docker
Docker mcp Gateway

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server structure for direct docker:// references and catalog snapshot imports in pkg/oci/self_contained.go and pkg/workingset/workingset.go. Runtime-shaping fields including Volumes, User, and ExtraHosts were then appended to the docker run argument vector without an origin allowlist, allowing a malicious image author to request host filesystem or Docker socket mounts and UID 0 execution when a victim selected or pulled the image. This container-creation-time boundary bypass can execute arbitrary code on the host and is not prevented by no-new-privileges because no in-container privilege escalation is required. This issue is fixed in version 0.42.2.
Title MCP Gateway: Argument injection via OCI image label YAML in Docker MCP Gateway
Weaknesses CWE-88
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Docker Mcp Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T18:02:09.186Z

Reserved: 2026-06-17T16:59:42.760Z

Link: CVE-2026-55887

cve-icon Vulnrichment

Updated: 2026-09-15T17:45:44.551Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:16.667

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')