Description
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while ToolHive API and MCP proxy endpoints are reachable without authentication. A malicious or compromised MCP server can use the Docker gateway to contact host-local services, other ToolHive-managed MCP proxies, or the ToolHive control plane without escaping the container. This access can expose data and logs, invoke sibling MCP tools, alter process or workload state, and disrupt services. ToolHive Studio additionally sends network_isolation as false and overrides the backend's secure isolation default. This issue is fixed in ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Host Access via Lateral Movement
Action: Patch Immediately
AI Analysis

Impact

ToolHive’s CLI and Studio generate Model Context Protocol servers inside Docker containers. Prior to CLI 0.30.1 and Studio 0.38.0 the default network profile leaves host.docker.internal visible and the API and MCP proxy endpoints are reachable without authentication. A compromised or malicious MCP server can therefore contact services on the host, other ToolHive‑managed proxies or the control plane, exposing logs and data, or modifying process or workload state. The flaw is an instance of improper access control (CWE‑284) and missing authentication (CWE‑306).

Affected Systems

The vulnerability affects ToolHive CLI (stacklok:toolhive) versions earlier than 0.30.1 and ToolHive Studio (stacklok:toolhive‑studio) versions earlier than 0.38.0. Any deployment of these products that runs MCP server containers without explicit network isolation is impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, but no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to compromise an MCP server inside the same host; the attack vector is local rather than remote. Because the issue sits in the container network configuration, a compromise can facilitate lateral movement within the host and potentially to other services exposed through ToolHive. Upgrading to the fixed releases or re‑configuring the network isolation mitigates the risk.

Generated by OpenCVE AI on September 19, 2026 at 12:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ToolHive CLI to version 0.30.1 or newer.
  • Upgrade ToolHive Studio to version 0.38.0 or newer.
  • If an upgrade is not immediately possible, enforce network isolation for MCP server containers to prevent access to host.docker.internal and disable unauthenticated API/proxy endpoints.
  • Verify that no other containers can reach host.docker.internal by inspecting Docker network settings.

Generated by OpenCVE AI on September 19, 2026 at 12:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qg2g-g9w3-m5h8 ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Stacklok
Stacklok toolhive
Stacklok toolhive-studio
Vendors & Products Stacklok
Stacklok toolhive
Stacklok toolhive-studio

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while ToolHive API and MCP proxy endpoints are reachable without authentication. A malicious or compromised MCP server can use the Docker gateway to contact host-local services, other ToolHive-managed MCP proxies, or the ToolHive control plane without escaping the container. This access can expose data and logs, invoke sibling MCP tools, alter process or workload state, and disrupt services. ToolHive Studio additionally sends network_isolation as false and overrides the backend's secure isolation default. This issue is fixed in ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0.
Title ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
Weaknesses CWE-284
CWE-306
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Stacklok Toolhive Toolhive-studio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T16:51:27.459Z

Reserved: 2026-06-29T17:09:25.871Z

Link: CVE-2026-58197

cve-icon Vulnrichment

Updated: 2026-09-18T16:51:22.063Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T17:16:57.880

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-58197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:22Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function