VulnerabilitiesToolHive containers can reach host services, advisory warns
A GitHub security advisory published on 18 September 2026 says Stacklok's ToolHive lets sandboxed MCP servers call the host, undermining its isolation model.
18 Sept 2026
Containerized MCP servers in ToolHive can reach host services through host.docker.internal, enabling lateral movement and tool manipulation. This bypasses the container isolation model that is ToolHive's core security feature.
Disclosed 18 September 2026 · Record updated 18 September 2026
Compromised or malicious MCP servers can perform lateral movement to reach the ToolHive control plane, other MCP server proxies, and host services including Kubernetes APIs and LLM services without container escape.
VulnerabilitiesA GitHub security advisory published on 18 September 2026 says Stacklok's ToolHive lets sandboxed MCP servers call the host, undermining its isolation model.
18 Sept 2026