Impact
Docker MCP Gateway allows deployment of MCP servers, and from release 0.21.0 to 0.42.2 it YAML‑unmarshalled the attacker‑controlled io.docker.server.metadata OCI image label into the catalog.Server structure used for docker:// references and catalog snapshot imports. Runtime‑shaping fields such as Volumes, User, and ExtraHosts were appended directly to the docker run argument vector without any origin allowlist. A malicious image author can therefore request host filesystem or Docker socket mounts and launch a container with UID 0, enabling the execution of arbitrary code on the host at container start time. This container‑creation‑time boundary bypass is not mitigated by no‑new‑privileges because no in‑container privilege escalation is required. The vulnerability is fixed in version 0.42.2 and is classified as CWE‑88.
Affected Systems
All deployments of Docker MCP Gateway running any release from version 0.21.0 through 0.42.1 are vulnerable. The flaw was addressed with the release of 0.42.2; any instance that has not been updated to that version remains susceptible.
Risk and Exploitability
The CVSS base score of 8.7 signals high severity, while the EPSS value of less than 1 % indicates a very low, but not zero, probability of exploitation. No special privileges are needed beyond pulling a malicious image; an attacker can achieve host‑level code execution simply by installing or pulling the compromised OCI image. This vulnerability is not listed in CISA’s KEV catalog, yet the combination of high impact and easy exploitation path warrants urgent attention.
OpenCVE Enrichment
Github GHSA