CVE-2026-58197: CWE-284: Improper Access Control in stacklok toolhive
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while ToolHive API and MCP proxy endpoints are reachable without authentication. A malicious or compromised MCP server can use the Docker gateway to contact host-local services, other ToolHive-managed MCP proxies, or the ToolHive control plane without escaping the container. This access can expose data and logs, invoke sibling MCP tools, alter process or workload state, and disrupt services. ToolHive Studio additionally sends network_isolation as false and overrides the backend's secure isolation default. This issue is fixed in ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0.
AI Analysis
Technical Summary
ToolHive is a utility for deploying and managing Model Context Protocol (MCP) servers. Before versions CLI 0.30.1 and Studio 0.38.0, MCP server containers run locally with default network permissions lacking isolation, permitting access to host.docker.internal and unauthenticated access to ToolHive API and MCP proxy endpoints. A malicious or compromised MCP server container can leverage this to contact host-local services, other MCP proxies, or the control plane without escaping the container. This improper access control (CWE-284) and lack of authentication (CWE-306) can expose sensitive data and logs, allow invocation of sibling MCP tools, alter process or workload state, and disrupt services. ToolHive Studio also overrides the backend's secure isolation default by sending network_isolation as false. The issue is resolved in ToolHive CLI 0.30.1 and Studio 0.38.0.
Potential Impact
The vulnerability allows a malicious or compromised MCP server container to access host-local services and internal ToolHive endpoints without authentication, potentially exposing sensitive data and logs, enabling unauthorized invocation of sibling MCP tools, altering process or workload states, and disrupting services. This can lead to significant confidentiality, integrity, and availability impacts within affected environments.
Mitigation Recommendations
This vulnerability is fixed in ToolHive CLI version 0.30.1 and ToolHive Studio version 0.38.0. Users should upgrade to these versions or later to ensure network isolation is properly enforced and unauthenticated access to internal endpoints is prevented.
CVE-2026-58197: CWE-284: Improper Access Control in stacklok toolhive
Description
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while ToolHive API and MCP proxy endpoints are reachable without authentication. A malicious or compromised MCP server can use the Docker gateway to contact host-local services, other ToolHive-managed MCP proxies, or the ToolHive control plane without escaping the container. This access can expose data and logs, invoke sibling MCP tools, alter process or workload state, and disrupt services. ToolHive Studio additionally sends network_isolation as false and overrides the backend's secure isolation default. This issue is fixed in ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0.
CVSS v3.1
Score 8.8high
Affected software
stacklok
toolhive
stacklok
toolhive-studio
pkg:github/stacklok/toolhive-studioRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ToolHive is a utility for deploying and managing Model Context Protocol (MCP) servers. Before versions CLI 0.30.1 and Studio 0.38.0, MCP server containers run locally with default network permissions lacking isolation, permitting access to host.docker.internal and unauthenticated access to ToolHive API and MCP proxy endpoints. A malicious or compromised MCP server container can leverage this to contact host-local services, other MCP proxies, or the control plane without escaping the container. This improper access control (CWE-284) and lack of authentication (CWE-306) can expose sensitive data and logs, allow invocation of sibling MCP tools, alter process or workload state, and disrupt services. ToolHive Studio also overrides the backend's secure isolation default by sending network_isolation as false. The issue is resolved in ToolHive CLI 0.30.1 and Studio 0.38.0.
Potential Impact
The vulnerability allows a malicious or compromised MCP server container to access host-local services and internal ToolHive endpoints without authentication, potentially exposing sensitive data and logs, enabling unauthorized invocation of sibling MCP tools, altering process or workload states, and disrupting services. This can lead to significant confidentiality, integrity, and availability impacts within affected environments.
Mitigation Recommendations
This vulnerability is fixed in ToolHive CLI version 0.30.1 and ToolHive Studio version 0.38.0. Users should upgrade to these versions or later to ensure network isolation is properly enforced and unauthenticated access to internal endpoints is prevented.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-29T17:09:25.871Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aad6b0a55bf5e2cf541929b
Added to database: 09/18/2026, 16:47:06 UTC
Last enriched: 09/18/2026, 17:01:32 UTC
Last updated: 09/18/2026, 22:12:51 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.