{"id":"CVE-2026-55887","summary":"MCP Gateway: Argument injection via OCI image label YAML in Docker MCP Gateway","details":"MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server structure for direct docker:// references and catalog snapshot imports in pkg/oci/self_contained.go and pkg/workingset/workingset.go. Runtime-shaping fields including Volumes, User, and ExtraHosts were then appended to the docker run argument vector without an origin allowlist, allowing a malicious image author to request host filesystem or Docker socket mounts and UID 0 execution when a victim selected or pulled the image. This container-creation-time boundary bypass can execute arbitrary code on the host and is not prevented by no-new-privileges because no in-container privilege escalation is required. This issue is fixed in version 0.42.2.","aliases":["GHSA-r2xf-7jw5-pjg6","GO-2026-5604"],"modified":"2026-09-17T03:47:26.846604668Z","published":"2026-09-15T15:45:36.420Z","related":["openSUSE-SU-2026:21483-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55887.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-88"]},"references":[{"type":"WEB","url":"https://github.com/docker/mcp-gateway/releases/tag/v0.42.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55887.json"},{"type":"ADVISORY","url":"https://github.com/docker/mcp-gateway/security/advisories/GHSA-r2xf-7jw5-pjg6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55887"},{"type":"FIX","url":"https://github.com/docker/mcp-gateway/commit/306d2d94a3b526f43281313321bf784f2d46a7fe"},{"type":"FIX","url":"https://github.com/docker/mcp-gateway/commit/439b2200d9e26a4ff414aeb043785df45a78422b"},{"type":"FIX","url":"https://github.com/docker/mcp-gateway/pull/498"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/docker/mcp-gateway","events":[{"introduced":"0c107cb99dc7a456ea4420457289896e7c6e2d0b"},{"fixed":"306d2d94a3b526f43281313321bf784f2d46a7fe"},{"fixed":"439b2200d9e26a4ff414aeb043785df45a78422b"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0.21.0"},{"fixed":"0.42.2"}]}}],"versions":["v0.42.1","v0.42.0","v0.40.4","v0.40.2","v0.41.0","v0.40.1","v0.40.0","v0.39.3","v0.39.2","v0.39.0","v0.38.0","v0.37.0","v0.36.0","v0.35.0","v0.34.0","v0.33.0","v0.32.0","v0.31.0","v0.30.0","v0.29.0","v0.28.0","v0.27.0","v0.26.0","v0.25.0","v0.24.0","v0.23.0","v0.22.0","v0.21.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55887.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}