Impact
ToolHive's authentication discovery routine accepts a WWW-Authenticate header with an embedded URL, blindly follows any redirects from the server, and lacks restrictions on destination host or scheme. This permits a malicious MCP server to instruct the client to contact any address reachable from the client, including link‑local, RFC1918, or provider metadata services, thereby enabling internal reconnaissance and extraction of short‑lived credentials. The flaw is identified as CWE‑918, a server‑side request forgery mechanism that undermines confidentiality of internal infrastructure. The CVSS score of 4.7 indicates moderate severity; the EPSS score is <1% and the vulnerability is not listed in CISA KEV, implying a low but non-zero exploitation risk.
Affected Systems
All releases of ToolHive built by Stacklok prior to version 0.31.0 are affected. The issue exists in the pkg/auth/remote/handler.go and pkg/auth/discovery/discovery.go modules that perform authentication discovery during client initialization. Users running those defaults are vulnerable until the update is applied.
Risk and Exploitability
The vulnerability requires an attacker to control or compromise a remote MCP server that a client will connect to. Once such a server responds with a crafted WWW-Authenticate header containing a resource_metadata URL, the client will issue HTTP GET requests to that address, following redirects without host or scheme validation. The exploit path does not rely on NAT64 guard omission; it directly bypasses container isolation for the client. Successful exploitation can reveal the presence of internal web services, expose AWS IMDSv1 metadata points, or enumerate other internal endpoints, providing opportunities for credential theft. The potential impact is limited to the connectivity of the affected client; however, any client that authenticates against the malicious server can be used as a foothold to probe the internal network. The CVSS score of 4.7 indicates moderate severity, and the EPSS score is reported as <1%, implying a low yet non-zero exploitation probability. It is not listed in CISA KEV.
OpenCVE Enrichment
Github GHSA