CVE-2026-58197
8.8Stacklok · ToolHive (CLI and Studio)
Stacklok ToolHive containers lack network isolation and permit unauthenticated access to sensitive endpoints, allowing compromised MCP servers to interact with host services and the control plane.
Executive summary
A critical security flaw in Stacklok ToolHive allows unauthenticated, container-based attacks to access host services and manipulate the control plane due to improper network isolation.
Vulnerability
The software fails to enforce network isolation for Model Context Protocol (MCP) server containers and lacks authentication for API and proxy endpoints. An attacker can leverage a compromised MCP server to communicate with host local services or the ToolHive control plane, effectively bypassing container boundary protections.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting a high potential for total compromise of the affected environment. Successful exploitation allows unauthorized parties to exfiltrate sensitive data, manipulate internal workloads, and disrupt critical business services managed by the ToolHive platform.
Remediation
Immediate Action: Update ToolHive CLI to version 0.30.1 or later, and ToolHive Studio to version 0.38.0 or later, to restore proper network isolation and authentication requirements.
Proactive Monitoring: Monitor logs for unauthorized access attempts to internal management APIs and investigate any unexpected network traffic originating from MCP server containers toward the host gateway.
Compensating Controls: Implement strict network security group rules or firewall policies that restrict container access to host local services, and ensure that ToolHive deployments are placed within trusted network segments.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for full control plane compromise and lateral movement within the host environment, organizations must prioritize upgrading to the patched versions immediately. Administrators should treat this as a high-priority remediation task to prevent unauthorized access to sensitive infrastructure and data flows managed by ToolHive.
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- https://github.com/stacklok/toolhive/security/advisories/GHSA-qg2g-g9w3-m5h8
- https://github.com/stacklok/toolhive-studio/pull/2469
- https://github.com/stacklok/toolhive/pull/5583
- https://github.com/stacklok/toolhive-studio/commit/968182d7f3ee1e55123369e66ad88f82128119b0
- https://github.com/stacklok/toolhive/commit/d8f40cb1599b8bf66657f2dfff15bfbfc236e712
- https://github.com/stacklok/toolhive-studio/releases/tag/v0.38.0
- https://github.com/stacklok/toolhive/releases/tag/v0.30.1