Skip to main content

CVE-2026-58197: CWE-284: Improper Access Control in stacklok toolhive

0
High
VulnerabilityCVE-2026-58197cvecve-2026-58197cwe-284cwe-306
Published: 09/18/2026 (09/18/2026, 16:34:55 UTC)
Source: CVE Database V5
Vendor/Project: stacklok
Product: toolhive

Description

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while ToolHive API and MCP proxy endpoints are reachable without authentication. A malicious or compromised MCP server can use the Docker gateway to contact host-local services, other ToolHive-managed MCP proxies, or the ToolHive control plane without escaping the container. This access can expose data and logs, invoke sibling MCP tools, alter process or workload state, and disrupt services. ToolHive Studio additionally sends network_isolation as false and overrides the backend's secure isolation default. This issue is fixed in ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0.

CVSS v3.1

Score 8.8high

Attack Vector
Adjacent Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected software

stacklok

toolhive

Affected versions
<0.30.1

stacklok

toolhive-studio

Affected versions
<0.38.0
GitHub Actionsmore threats →ai
stacklok/toolhive
pkg:github/stacklok/toolhive
Affected versions
<0.30.1
GitHub Actionsmore threats →ai
stacklok/toolhive-studio
pkg:github/stacklok/toolhive-studio
Affected versions
<0.38.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 17:01:32 UTC

Technical Analysis

ToolHive is a utility for deploying and managing Model Context Protocol (MCP) servers. Before versions CLI 0.30.1 and Studio 0.38.0, MCP server containers run locally with default network permissions lacking isolation, permitting access to host.docker.internal and unauthenticated access to ToolHive API and MCP proxy endpoints. A malicious or compromised MCP server container can leverage this to contact host-local services, other MCP proxies, or the control plane without escaping the container. This improper access control (CWE-284) and lack of authentication (CWE-306) can expose sensitive data and logs, allow invocation of sibling MCP tools, alter process or workload state, and disrupt services. ToolHive Studio also overrides the backend's secure isolation default by sending network_isolation as false. The issue is resolved in ToolHive CLI 0.30.1 and Studio 0.38.0.

Potential Impact

The vulnerability allows a malicious or compromised MCP server container to access host-local services and internal ToolHive endpoints without authentication, potentially exposing sensitive data and logs, enabling unauthorized invocation of sibling MCP tools, altering process or workload states, and disrupting services. This can lead to significant confidentiality, integrity, and availability impacts within affected environments.

Mitigation Recommendations

This vulnerability is fixed in ToolHive CLI version 0.30.1 and ToolHive Studio version 0.38.0. Users should upgrade to these versions or later to ensure network isolation is properly enforced and unauthenticated access to internal endpoints is prevented.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-29T17:09:25.871Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aad6b0a55bf5e2cf541929b

Added to database: 09/18/2026, 16:47:06 UTC

Last enriched: 09/18/2026, 17:01:32 UTC

Last updated: 09/18/2026, 22:12:51 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses