{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3astackloktoolhive/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:stacklok:toolhive:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-58197"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ToolHive (\u003c 0.30.1)"],"_cs_severities":["high"],"_cs_tags":["container-security","mcp","lateral-movement","cve-2026-58197"],"_cs_type":"threat","_cs_vendors":["Stacklok"],"content_html":"\u003cp\u003eToolHive versions prior to 0.30.1 feature insecure default container networking configurations. By default, MCP servers run with an 'insecure_allow_all' permission profile, allowing containerized processes to communicate with the host machine via the Docker-provided 'host.docker.internal' hostname. Because the ToolHive control plane API and individual MCP proxy endpoints lack authentication, any compromised or malicious MCP server container can reach services listening on the host's localhost. This exposure allows an attacker to interact with the ToolHive API, other ToolHive-managed proxy services, the Kubernetes API, and host-local LLM APIs like Ollama. This flaw enables unauthorized lateral movement and command execution on the host machine without requiring a container escape vulnerability.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker deploys or compromises a containerized MCP server instance within the ToolHive environment.\u003c/li\u003e\n\u003cli\u003eAttacker performs internal network reconnaissance by scanning 'host.docker.internal' from within the container context.\u003c/li\u003e\n\u003cli\u003eAttacker identifies sensitive services listening on the host, such as the ToolHive control plane (port 50444) or Ollama (port 11434).\u003c/li\u003e\n\u003cli\u003eAttacker initiates an unauthenticated JSON-RPC MCP handshake with the discovered ToolHive control plane or proxy endpoints.\u003c/li\u003e\n\u003cli\u003eAttacker leverages discovered MCP tool capabilities to interact with host resources, such as reading files or executing system commands.\u003c/li\u003e\n\u003cli\u003eAttacker pivots to privileged native MCP tools residing on the host that lack granular access control.\u003c/li\u003e\n\u003cli\u003eAttacker achieves unauthorized host-level actions or data exfiltration based on the permissions of the targeted local service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to perform lateral movement from an isolated container environment to the host system. Impact includes the potential for unauthorized code execution, full exfiltration of data handled by other MCP servers, manipulation of the ToolHive configuration, and unauthorized use of LLM model inference APIs. The vulnerability affects users of the ToolHive desktop application and Docker runtime environments, specifically those running versions prior to 0.30.1.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all ToolHive deployments to version 0.30.1 or later to remediate the insecure default container networking settings.\u003c/li\u003e\n\u003cli\u003eImplement strict network policy controls to block 'host.docker.internal' and '172.17.0.1' access for all containerized MCP servers by default.\u003c/li\u003e\n\u003cli\u003eTransition to explicit allow-lists for container network communication within ToolHive permission profiles.\u003c/li\u003e\n\u003cli\u003eImplement authentication mechanisms, such as tokens or mutual TLS, for all inter-service communication between the ToolHive proxy and individual MCP servers.\u003c/li\u003e\n\u003cli\u003eEnable audit logging for all MCP tool calls to improve detection of unauthorized inter-server or host-access attempts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T19:51:12Z","date_published":"2026-09-18T19:51:12Z","id":"https://feed.craftedsignal.io/briefs/2026-09-toolhive-container-pivot/","summary":"ToolHive versions prior to 0.30.1 enable insecure container network defaults that allow MCP servers to reach host services via host.docker.internal, enabling unauthenticated lateral movement and host API exploitation.","title":"ToolHive Containerized MCP Servers Vulnerable to Host Pivot and Lateral Movement","url":"https://feed.craftedsignal.io/briefs/2026-09-toolhive-container-pivot/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:stacklok:toolhive:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}