<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 19:28:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-371966</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-371966</link>
      <description>EUVD-2026-371966</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-371966</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58197</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58197</link>
      <description>&lt;p&gt;ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while ToolHive API and MCP proxy endpoints are reachable without authentication. A malicious or compromised MCP server can use the Docker gateway to contact host-local services, other ToolHive-managed MCP proxies, or the ToolHive control plane without escaping the container. This access can expose data and logs, invoke sibling MCP tools, alter process or workload state, and disrupt services. ToolHive Studio additionally sends network_isolation as false and overrides the backend&amp;#39;s secure isolation default. This issue is fixed in ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while ToolHive API and MCP proxy endpoints are reachable without authentication. A malicious or compromised MCP server can use the Docker gateway to contact host-local services, other ToolHive-managed MCP proxies, or the ToolHive control plane without escaping the container. This access can expose data and logs, invoke sibling MCP tools, alter process or workload state, and disrupt services. ToolHive Studio additionally sends network_isolation as false and overrides the backend&amp;#39;s secure isolation default. This issue is fixed in ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58197</guid>
    </item>
    <item>
      <title>GHSA-qg2g-g9w3-m5h8 — ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qg2g-g9w3-m5h8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/stacklok/toolhive&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A containerized MCP server running with the default `network` permission profile (`insecure_allow_all: true`) can reach host-local services via `host.docker.internal`. This includes the ToolHive API itself, other ToolHive-managed MCP server proxies, and any other service listening on the host&amp;#39;s localhost. Combined with the unauthenticated ToolHive API and MCP proxy endpoints, this enables a compromised or malicious MCP server to perform lateral movement without any container escape.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**High** — This bypasses the container isolation model that is ToolHive&amp;#39;s core security value proposition.&lt;/p&gt;
&lt;p&gt;## Reproduction&lt;/p&gt;
&lt;p&gt;All tests performed from inside the `filesystem` MCP container (`docker.io/mcp/filesystem:latest`), started with default settings via `thv run filesystem -- /tmp`.&lt;/p&gt;
&lt;p&gt;### 1. Container can reach the ToolHive control plane MCP endpoint&lt;/p&gt;
&lt;p&gt;```bash
$ docker exec &amp;lt;container_id&amp;gt; wget -qO- \
  --header=&amp;#34;Content-Type: application/json&amp;#34; \
  --header=&amp;#34;Accept: application/json&amp;#34; \
  --post-data=&amp;#39;{&amp;#34;jsonrpc&amp;#34;:&amp;#34;2.0&amp;#34;,&amp;#34;method&amp;#34;:&amp;#34;initialize&amp;#34;,&amp;#34;params&amp;#34;:{&amp;#34;protocolVersion&amp;#34;:&amp;#34;2025-03-26&amp;#34;,&amp;#34;capabilities&amp;#34;:{},&amp;#34;clientInfo&amp;#34;:{&amp;#34;name&amp;#34;:&amp;#34;evil-mcp&amp;#34;,&amp;#34;version&amp;#34;:&amp;#34;1.0&amp;#34;}},&amp;#34;id&amp;#34;:1}&amp;#39; \
  http://host.docker.internal:50444/mcp
```&lt;/p&gt;
&lt;p&gt;**Result:** Full MCP handshake succeeds:
```json
{&amp;#34;jsonrpc&amp;#34;:&amp;#34;2.0&amp;#34;,&amp;#34;id&amp;#34;:1,&amp;#34;result&amp;#34;:{&amp;#34;protocolVersion&amp;#34;:&amp;#34;2025-03-26&amp;#34;,&amp;#34;capabilities&amp;#34;:{&amp;#34;logging&amp;#34;:{},&amp;#34;tools&amp;#34;:{}},&amp;#34;serverInfo&amp;#34;:{&amp;#34;name&amp;#34;:&amp;#34;toolhive-mcp&amp;#34;,&amp;#34;version&amp;#34;:&amp;#34;v0.9.3&amp;#34;}}}
```&lt;/p&gt;
&lt;p&gt;### 2. Container can connect to another MCP server&amp;#39;s pr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/stacklok/toolhive&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A containerized MCP server running with the default `network` permission profile (`insecure_allow_all: true`) can reach host-local services via `host.docker.internal`. This includes the ToolHive API itself, other ToolHive-managed MCP server proxies, and any other service listening on the host&amp;#39;s localhost. Combined with the unauthenticated ToolHive API and MCP proxy endpoints, this enables a compromised or malicious MCP server to perform lateral movement without any container escape.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**High** — This bypasses the container isolation model that is ToolHive&amp;#39;s core security value proposition.&lt;/p&gt;
&lt;p&gt;## Reproduction&lt;/p&gt;
&lt;p&gt;All tests performed from inside the `filesystem` MCP container (`docker.io/mcp/filesystem:latest`), started with default settings via `thv run filesystem -- /tmp`.&lt;/p&gt;
&lt;p&gt;### 1. Container can reach the ToolHive control plane MCP endpoint&lt;/p&gt;
&lt;p&gt;```bash
$ docker exec &amp;lt;container_id&amp;gt; wget -qO- \
  --header=&amp;#34;Content-Type: application/json&amp;#34; \
  --header=&amp;#34;Accept: application/json&amp;#34; \
  --post-data=&amp;#39;{&amp;#34;jsonrpc&amp;#34;:&amp;#34;2.0&amp;#34;,&amp;#34;method&amp;#34;:&amp;#34;initialize&amp;#34;,&amp;#34;params&amp;#34;:{&amp;#34;protocolVersion&amp;#34;:&amp;#34;2025-03-26&amp;#34;,&amp;#34;capabilities&amp;#34;:{},&amp;#34;clientInfo&amp;#34;:{&amp;#34;name&amp;#34;:&amp;#34;evil-mcp&amp;#34;,&amp;#34;version&amp;#34;:&amp;#34;1.0&amp;#34;}},&amp;#34;id&amp;#34;:1}&amp;#39; \
  http://host.docker.internal:50444/mcp
```&lt;/p&gt;
&lt;p&gt;**Result:** Full MCP handshake succeeds:
```json
{&amp;#34;jsonrpc&amp;#34;:&amp;#34;2.0&amp;#34;,&amp;#34;id&amp;#34;:1,&amp;#34;result&amp;#34;:{&amp;#34;protocolVersion&amp;#34;:&amp;#34;2025-03-26&amp;#34;,&amp;#34;capabilities&amp;#34;:{&amp;#34;logging&amp;#34;:{},&amp;#34;tools&amp;#34;:{}},&amp;#34;serverInfo&amp;#34;:{&amp;#34;name&amp;#34;:&amp;#34;toolhive-mcp&amp;#34;,&amp;#34;version&amp;#34;:&amp;#34;v0.9.3&amp;#34;}}}
```&lt;/p&gt;
&lt;p&gt;### 2. Container can connect to another MCP server&amp;#39;s pr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qg2g-g9w3-m5h8</guid>
    </item>
  </channel>
</rss>
