CVE-2026-58197
high
CVSS v3
8.8
CVSS v4 NEW
—
VIR risk
8.8
Description
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
Predictions
Exploit likelihood
82%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | github.com/stacklok/toolhive | <0.30.1 | 0.30.1 |
References
- https://github.com/stacklok/toolhive-studio/commit/968182d7f3ee1e55123369e66ad88f82128119b0
- https://github.com/stacklok/toolhive-studio/pull/2469
- https://github.com/stacklok/toolhive-studio/releases/tag/v0.38.0
- https://github.com/stacklok/toolhive/commit/d8f40cb1599b8bf66657f2dfff15bfbfc236e712
- https://github.com/stacklok/toolhive/pull/5583
- https://github.com/stacklok/toolhive/releases/tag/v0.30.1
- https://github.com/stacklok/toolhive/security/advisories/GHSA-qg2g-g9w3-m5h8
- https://github.com/stacklok/toolhive
CWEs
CWE-284 CWE-306
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.