GHSA-qg2g-g9w3-m5h8
HIGHCVE-2026-58197A containerized MCP server running with the default network permission profile (insecureallowall: true) can reach host-local services via host.docker.internal. This includes the ToolHive API itself, other ToolHive-managed MCP server proxies, and any other service listening on the host's localhost. Combined with the unauthenticated ToolHive API and MCP proxy endpoints, this enables a compromised or
- Affected
- < 0.30.1, >=0, <0.30.1
- Fixed in
- 0.30.1
- Weakness
- CWE-284
- Published
- 2026-09-18
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereference