| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r2xf-7jw5-pjg6 | Docker MCP Gateway: Argument injection via OCI image label YAML |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Docker
Docker mcp Gateway |
|
| Vendors & Products |
Docker
Docker mcp Gateway |
Tue, 15 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server structure for direct docker:// references and catalog snapshot imports in pkg/oci/self_contained.go and pkg/workingset/workingset.go. Runtime-shaping fields including Volumes, User, and ExtraHosts were then appended to the docker run argument vector without an origin allowlist, allowing a malicious image author to request host filesystem or Docker socket mounts and UID 0 execution when a victim selected or pulled the image. This container-creation-time boundary bypass can execute arbitrary code on the host and is not prevented by no-new-privileges because no in-container privilege escalation is required. This issue is fixed in version 0.42.2. | |
| Title | MCP Gateway: Argument injection via OCI image label YAML in Docker MCP Gateway | |
| Weaknesses | CWE-88 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T18:02:09.186Z
Reserved: 2026-06-17T16:59:42.760Z
Link: CVE-2026-55887
Updated: 2026-09-15T17:45:44.551Z
Status : Received
Published: 2026-09-15T16:17:16.667
Modified: 2026-09-15T19:17:23.150
Link: CVE-2026-55887
No data.
OpenCVE Enrichment
Updated: 2026-09-15T18:45:18Z
Github GHSA