Impact
ToolHive’s CLI and Studio generate Model Context Protocol servers inside Docker containers. Prior to CLI 0.30.1 and Studio 0.38.0 the default network profile leaves host.docker.internal visible and the API and MCP proxy endpoints are reachable without authentication. A compromised or malicious MCP server can therefore contact services on the host, other ToolHive‑managed proxies or the control plane, exposing logs and data, or modifying process or workload state. The flaw is an instance of improper access control (CWE‑284) and missing authentication (CWE‑306).
Affected Systems
The vulnerability affects ToolHive CLI (stacklok:toolhive) versions earlier than 0.30.1 and ToolHive Studio (stacklok:toolhive‑studio) versions earlier than 0.38.0. Any deployment of these products that runs MCP server containers without explicit network isolation is impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to compromise an MCP server inside the same host; the attack vector is local rather than remote. Because the issue sits in the container network configuration, a compromise can facilitate lateral movement within the host and potentially to other services exposed through ToolHive. Upgrading to the fixed releases or re‑configuring the network isolation mitigates the risk.
OpenCVE Enrichment
Github GHSA