<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T23:02:52.522393+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-371966</id>
    <title>EUVD-2026-371966</title>
    <updated>2026-10-06T23:02:52.570986+00:00</updated>
    <content>EUVD-2026-371966</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-371966"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58197</id>
    <title>fkie_cve-2026-58197</title>
    <updated>2026-10-06T23:02:52.571048+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while ToolHive API and MCP proxy endpoints are reachable without authentication. A malicious or compromised MCP server can use the Docker gateway to contact host-local services, other ToolHive-managed MCP proxies, or the ToolHive control plane without escaping the container. This access can expose data and logs, invoke sibling MCP tools, alter process or workload state, and disrupt services. ToolHive Studio additionally sends network_isolation as false and overrides the backend's secure isolation default. This issue is fixed in ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-58197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qg2g-g9w3-m5h8</id>
    <title>GHSA-qg2g-g9w3-m5h8 — ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement</title>
    <updated>2026-10-06T23:02:52.571119+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/stacklok/toolhive</p>
<p>## Summary</p>
<p>A containerized MCP server running with the default `network` permission profile (`insecure_allow_all: true`) can reach host-local services via `host.docker.internal`. This includes the ToolHive API itself, other ToolHive-managed MCP server proxies, and any other service listening on the host's localhost. Combined with the unauthenticated ToolHive API and MCP proxy endpoints, this enables a compromised or malicious MCP server to perform lateral movement without any container escape.</p>
<p>## Severity</p>
<p>**High** — This bypasses the container isolation model that is ToolHive's core security value proposition.</p>
<p>## Reproduction</p>
<p>All tests performed from inside the `filesystem` MCP container (`docker.io/mcp/filesystem:latest`), started with default settings via `thv run filesystem -- /tmp`.</p>
<p>### 1. Container can reach the ToolHive control plane MCP endpoint</p>
<p>```bash
$ docker exec &lt;container_id&gt; wget -qO- \
  --header="Content-Type: application/json" \
  --header="Accept: application/json" \
  --post-data='{"jsonrpc":"2.0","method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"evil-mcp","version":"1.0"}},"id":1}' \
  http://host.docker.internal:50444/mcp
```</p>
<p>**Result:** Full MCP handshake succeeds:
```json
{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2025-03-26","capabilities":{"logging":{},"tools":{}},"serverInfo":{"name":"toolhive-mcp","version":"v0.9.3"}}}
```</p>
<p>### 2. Container can connect to another MCP server's pr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qg2g-g9w3-m5h8"/>
  </entry>
</feed>
