Saturday, 19 September 2026
0 agent hacks today 8 vs yesterday (8)

ToolHive containerized MCP servers bypass isolation via host.docker.internal

Containerized MCP servers in ToolHive can reach host services through host.docker.internal, enabling lateral movement and tool manipulation. This bypasses the container isolation model that is ToolHive's core security feature.

Disclosed 18 September 2026 · Record updated 18 September 2026

Impact

Compromised or malicious MCP servers can perform lateral movement to reach the ToolHive control plane, other MCP server proxies, and host services including Kubernetes APIs and LLM services without container escape.

Our coverage

Sources

  1. github.comhttps://github.com/advisories/GHSA-qg2g-g9w3-m5h8