Vibe Coding
CVE-2026-58197: ToolHive's containerized MCP servers can reach host services and pivot laterally
Published 2026-09-18 at CVSS 8.8, the flaw affects ToolHive CLI before 0.30.1 and ToolHive Studio before 0.38.0: locally run MCP server containers use the default network permission profile with no network isolation, so they can reach host.docker.internal while the ToolHive API and MCP proxy endpoints themselves require no authentication. A malicious or compromised MCP server therefore uses the Docker gateway to contact host-local services and other ToolHive-managed servers. This is the sharpest version yet of the pattern that produced four of yesterday's five MCP CVEs, except here the container was the thing you thought was the boundary.
Source
↳ Follow the thread