PT-2026-95486 · Unknown · Toolhive Cli+1

CVE-2026-58197

·

Published

2026-09-18

·

Updated

2026-09-28

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ToolHive CLI versions prior to 0.30.1 ToolHive Studio versions prior to 0.38.0
Description Locally run Model Context Protocol (MCP) server containers use a default network permission profile that lacks network isolation. This allows containers to access host.docker.internal via the Docker gateway. Because the ToolHive API and MCP proxy endpoints are reachable without authentication, a malicious or compromised MCP server can perform lateral movement to contact host-local services, other ToolHive-managed MCP proxies, or the ToolHive control plane without needing to escape the container. This can lead to data and log exposure, the invocation of sibling MCP tools, alteration of process or workload states, and service disruption. ToolHive Studio further exacerbates this by sending network isolation as false, overriding the backend's secure isolation default. The issue is rooted in the use of insecure allow all: true as a default and the lack of authentication on API and proxy endpoints.
Recommendations Update ToolHive CLI to version 0.30.1. Update ToolHive Studio to version 0.38.0.

Exploit

Fix

Improper Access Control

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58197
GHSA-QG2G-G9W3-M5H8
GO-2026-6526

Affected Products

Toolhive Cli
Toolhive-Studio