{"id":"CVE-2026-58197","summary":"ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement","details":"ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while ToolHive API and MCP proxy endpoints are reachable without authentication. A malicious or compromised MCP server can use the Docker gateway to contact host-local services, other ToolHive-managed MCP proxies, or the ToolHive control plane without escaping the container. This access can expose data and logs, invoke sibling MCP tools, alter process or workload state, and disrupt services. ToolHive Studio additionally sends network_isolation as false and overrides the backend's secure isolation default. This issue is fixed in ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0.","aliases":["GHSA-qg2g-g9w3-m5h8"],"modified":"2026-09-20T11:46:49.622044663Z","published":"2026-09-18T16:34:55.213Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58197.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-284","CWE-306"]},"references":[{"type":"WEB","url":"https://github.com/stacklok/toolhive-studio/releases/tag/v0.38.0"},{"type":"WEB","url":"https://github.com/stacklok/toolhive/releases/tag/v0.30.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58197.json"},{"type":"ADVISORY","url":"https://github.com/stacklok/toolhive/security/advisories/GHSA-qg2g-g9w3-m5h8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58197"},{"type":"FIX","url":"https://github.com/stacklok/toolhive-studio/commit/968182d7f3ee1e55123369e66ad88f82128119b0"},{"type":"FIX","url":"https://github.com/stacklok/toolhive-studio/pull/2469"},{"type":"FIX","url":"https://github.com/stacklok/toolhive/commit/d8f40cb1599b8bf66657f2dfff15bfbfc236e712"},{"type":"FIX","url":"https://github.com/stacklok/toolhive/pull/5583"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/stacklok/toolhive","events":[{"introduced":"0"},{"fixed":"d8f40cb1599b8bf66657f2dfff15bfbfc236e712"},{"fixed":"966ca7c6ba1cf45ea156e2d08ed9ee5283bc0e01"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.30.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/stacklok/toolhive-studio","events":[{"introduced":"0"},{"fixed":"968182d7f3ee1e55123369e66ad88f82128119b0"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"0.38.0"}]}}],"versions":["v0.30.0","v0.29.3","v0.29.2","v0.29.1","v0.29.0","v0.28.3","v0.28.2","v0.28.1","v0.28.0","v0.27.2","v0.27.1","v0.27.0","v0.26.1","v0.26.0","v0.25.0","v0.24.1","v0.24.0","v0.23.1","v0.23.0","v0.22.0","v0.21.0","v0.20.0","v0.19.0","v0.18.0","v0.17.0","v0.16.0","v0.15.0","v0.14.1","v0.14.0","v0.13.1","v0.13.0","v0.12.5","v0.12.4","v0.12.3","v0.12.2","v0.12.1","v0.12.0","v0.11.3","v0.11.2","v0.11.1","v0.11.0","v0.10.2","v0.10.1","v0.10.0","v0.9.4","v0.9.3","v0.9.2","v0.9.1","v0.9.0","v0.8.3","toolhive-operator-crds-0.0.106","toolhive-operator-crds-0.0.105","v0.8.2","toolhive-operator-0.5.28","v0.8.1","toolhive-operator-crds-0.0.104","toolhive-operator-crds-0.0.103","toolhive-operator-0.5.27","toolhive-operator-crds-0.0.102","toolhive-operator-0.5.26","toolhive-operator-crds-0.0.101","toolhive-operator-crds-0.0.100","toolhive-operator-crds-0.0.99","v0.8.0","toolhive-operator-crds-0.0.98","toolhive-operator-crds-0.0.97","toolhive-operator-0.5.25","v0.7.2","toolhive-operator-0.5.24","v0.7.1","toolhive-operator-0.5.23","v0.7.0","toolhive-operator-crds-0.0.96","toolhive-operator-crds-0.0.95","toolhive-operator-0.5.22","toolhive-operator-crds-0.0.94","toolhive-operator-0.5.21","toolhive-operator-crds-0.0.93","toolhive-operator-crds-0.0.92","v0.6.17","toolhive-operator-crds-0.0.91","toolhive-operator-0.5.20","toolhive-operator-crds-0.0.90","toolhive-operator-crds-0.0.89","toolhive-operator-0.5.19","v0.6.16","toolhive-operator-0.5.18","toolhive-operator-crds-0.0.88","toolhive-operator-0.5.17","toolhive-operator-0.5.16","v0.6.15","toolhive-operator-crds-0.0.86","toolhive-operator-0.5.15","v0.6.14","toolhive-operator-0.5.14","toolhive-operator-crds-0.0.85","toolhive-operator-0.5.13","toolhive-operator-crds-0.0.84","v0.6.13","toolhive-operator-crds-0.0.83","toolhive-operator-0.5.12","v0.6.12","toolhive-operator-crds-0.0.82","toolhive-operator-crds-0.0.81","toolhive-operator-crds-0.0.80","toolhive-operator-crds-0.0.79","toolhive-operator-crds-0.0.78","toolhive-operator-0.5.11","toolhive-operator-0.5.10","toolhive-operator-crds-0.0.77","toolhive-operator-crds-0.0.76","toolhive-operator-crds-0.0.75","toolhive-operator-0.5.9","toolhive-operator-0.5.8","toolhive-operator-crds-0.0.74","v0.6.11","toolhive-operator-0.5.7","v0.6.10","toolhive-operator-0.5.6","toolhive-operator-crds-0.0.73","toolhive-operator-crds-0.0.72","toolhive-operator-0.5.5","toolhive-operator-0.5.4","v0.6.9","toolhive-operator-crds-0.0.71","toolhive-operator-crds-0.0.70","toolhive-operator-crds-0.0.69","toolhive-operator-crds-0.0.68","toolhive-operator-crds-0.0.67","v0.6.8","toolhive-operator-crds-0.0.66","toolhive-operator-crds-0.0.65","toolhive-operator-crds-0.0.64","toolhive-operator-crds-0.0.63","v0.6.7","toolhive-operator-crds-0.0.62","toolhive-operator-crds-0.0.61","toolhive-operator-crds-0.0.60","toolhive-operator-0.5.3","v0.6.6","toolhive-operator-crds-0.0.59","toolhive-operator-crds-0.0.58","toolhive-operator-0.5.2","toolhive-operator-crds-0.0.57","toolhive-operator-crds-0.0.56","v0.6.5","v0.6.4","v0.6.3","toolhive-operator-0.5.1","toolhive-operator-crds-0.0.55","toolhive-operator-0.5.0","v0.6.2","v0.6.1","toolhive-operator-crds-0.0.54","v0.6.0","toolhive-operator-crds-0.0.53","toolhive-operator-0.4.0","toolhive-operator-0.3.7","toolhive-operator-crds-0.0.52","toolhive-operator-crds-0.0.51","toolhive-operator-0.3.6","v0.5.2","toolhive-operator-crds-0.0.50","toolhive-operator-crds-0.0.49","toolhive-operator-0.3.5","toolhive-operator-crds-0.0.48","toolhive-operator-0.3.4","v0.5.1","toolhive-operator-crds-0.0.47","toolhive-operator-0.3.2","v0.5.0","toolhive-operator-crds-0.0.46","toolhive-operator-crds-0.0.45","toolhive-operator-crds-0.0.44","toolhive-operator-crds-0.0.43","toolhive-operator-0.3.1","v0.4.2","toolhive-operator-crds-0.0.42","v0.4.1","toolhive-operator-crds-0.0.41","toolhive-operator-crds-0.0.40","toolhive-operator-crds-0.0.39","toolhive-operator-0.3.0","v0.4.0","toolhive-operator-crds-0.0.38","toolhive-operator-0.2.26","toolhive-operator-0.2.25","toolhive-operator-0.2.24","v0.3.11","v0.3.10","toolhive-operator-crds-0.0.36","v0.3.9","toolhive-operator-crds-0.0.35","toolhive-operator-0.2.23","toolhive-operator-0.2.22","v0.3.8","toolhive-operator-crds-0.0.34","toolhive-operator-0.2.21","toolhive-operator-crds-0.0.33","toolhive-operator-0.2.20","v0.3.7","toolhive-operator-crds-0.0.32","toolhive-operator-crds-0.0.31","v0.3.6","toolhive-operator-0.2.19","toolhive-operator-crds-0.0.30","toolhive-operator-crds-0.0.29","toolhive-operator-crds-0.0.27","toolhive-operator-0.2.18","toolhive-operator-0.2.17","v0.3.5","v0.3.4","toolhive-operator-0.2.16","toolhive-operator-0.2.15","v0.3.3","toolhive-operator-crds-0.0.26","v0.3.2","v0.3.1","toolhive-operator-crds-0.0.25","toolhive-operator-0.2.14","v0.3.0","toolhive-operator-0.2.13","toolhive-operator-crds-0.0.24","toolhive-operator-crds-0.0.23","toolhive-operator-0.2.12","toolhive-operator-crds-0.0.22","toolhive-operator-crds-0.0.21","toolhive-operator-0.2.11","v0.2.17","toolhive-operator-0.2.8","toolhive-operator-crds-0.0.19","v0.2.16","v0.2.15","v0.2.14","toolhive-operator-crds-0.0.18","toolhive-operator-crds-0.0.17","v0.2.13","v0.2.12","toolhive-operator-crds-0.0.16","v0.2.11","v0.2.10","v0.2.9","toolhive-operator-0.2.6","toolhive-operator-0.2.5","toolhive-operator-0.2.4","v0.2.8","toolhive-operator-0.2.3","toolhive-operator-crds-0.0.15","toolhive-operator-0.2.2","toolhive-operator-crds-0.0.14","v0.2.7","v0.2.6","v0.2.5","v0.2.4","toolhive-operator-crds-0.0.13","v0.2.3","v0.2.2","v0.2.1","toolhive-operator-crds-0.0.12","toolhive-operator-0.2.1","toolhive-operator-0.2.0","v0.2.0","v0.1.9","toolhive-operator-0.1.8","v0.1.8","toolhive-operator-crds-0.0.11","toolhive-operator-crds-0.0.10","v0.1.7","v0.1.6","toolhive-operator-0.1.5","v0.1.5","v0.1.4","v0.1.3","v0.1.2","toolhive-operator-crds-0.0.9","toolhive-operator-crds-0.0.8","v0.1.1","toolhive-operator-0.1.0","v0.1.0","v0.0.48","toolhive-operator-crds-0.0.7","v0.0.47","v0.0.46","toolhive-operator-0.0.11","v0.0.45","v0.0.44","v0.0.43","toolhive-operator-0.0.10","v0.0.42","v0.0.41","v0.0.40","toolhive-operator-crds-0.0.6","toolhive-operator-crds-0.0.5","toolhive-operator-0.0.9","toolhive-operator-0.0.8","v0.0.39","toolhive-operator-crds-0.0.4","toolhive-operator-0.0.7","v0.0.38","toolhive-operator-0.0.6","v0.0.37","toolhive-operator-0.0.5","v0.0.36","v0.0.35","toolhive-operator-0.0.4","v0.0.34","toolhive-operator-crds-0.0.3","toolhive-operator-0.0.3","v0.0.33","v0.0.32","v0.0.31","v0.0.30","v0.0.29","v0.0.28","v0.0.27","v0.0.26","v0.0.25","v0.0.24","v0.0.23","v0.0.22","v0.0.21","v0.0.20","v0.0.19","v0.0.18","v0.0.17","v0.0.16","v0.0.15","v0.0.14","v0.0.13","v0.0.12","v0.0.11","v0.0.10","v0.0.9","v0.0.8","v0.0.7","v0.0.6","v0.0.5","v0.0.4","v0.0.3","v0.0.2","v0.0.1","v0.37.0-rc.1","v0.37.0","v0.37.0-rc.0","v0.36.7-rc.0","v0.36.7","v0.36.6-rc.3","v0.36.6-rc.2","v0.36.6","v0.36.6-rc.1","v0.36.6-rc.0","v0.36.5-rc.0","v0.36.5","v0.36.4","v0.36.3-rc.0","v0.36.3-rc.1","v0.36.3","v0.36.2-rc.0","v0.36.2","v0.36.1-rc.0","v0.36.1","v0.36.0-rc.0","v0.36.0","v0.35.4","v0.35.3","v0.35.3-rc.1","v0.35.3-rc.0","v0.35.2","v0.35.1-rc.0","v0.35.1","v0.35.0","v0.35.0-rc.2","v0.35.0-rc.1","v0.35.0-rc.0","v0.34.0","v0.34.0-rc.1","v0.34.0-rc.0","v0.33.1-rc.0","v0.33.1","v0.33.0-rc.0","v0.33.0","v0.32.1-rc.0","v0.32.1","v0.32.0-rc.1","v0.32.0","v0.32.0-rc.0","v0.31.0","v0.31.0-rc.0","v0.30.0-rc.0","v0.28.0-rc.0","v0.27.0-rc.0","v0.26.0-rc.0","v0.25.0-rc.0","v0.22.1-rc.0","v0.22.0-rc.2","v0.22.0-rc.1","v0.22.0-rc.0","v0.20.0-rc.0","v0.19.1","v0.19.0-rc.1","v0.19.0-rc.0","v0.18.1-rc.1","v0.18.1","v0.0.0-dev","v0.18.0-rc.1","v0.17.3","v0.17.2","v0.17.1-rc.1","v0.17.1","v0.15.1","v0.13.3","v0.13.2","v0.5.5","v0.5.4","v0.5.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58197.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}