PT-2026-95486 · Unknown · Toolhive Cli+1
CVE-2026-58197
·
Published
2026-09-18
·
Updated
2026-09-28
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ToolHive CLI versions prior to 0.30.1
ToolHive Studio versions prior to 0.38.0
Description
Locally run Model Context Protocol (MCP) server containers use a default network permission profile that lacks network isolation. This allows containers to access
host.docker.internal via the Docker gateway. Because the ToolHive API and MCP proxy endpoints are reachable without authentication, a malicious or compromised MCP server can perform lateral movement to contact host-local services, other ToolHive-managed MCP proxies, or the ToolHive control plane without needing to escape the container. This can lead to data and log exposure, the invocation of sibling MCP tools, alteration of process or workload states, and service disruption. ToolHive Studio further exacerbates this by sending network isolation as false, overriding the backend's secure isolation default. The issue is rooted in the use of insecure allow all: true as a default and the lack of authentication on API and proxy endpoints.Recommendations
Update ToolHive CLI to version 0.30.1.
Update ToolHive Studio to version 0.38.0.
Exploit
Fix
Improper Access Control
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Toolhive Cli
Toolhive-Studio