Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55887— MCP Gateway: Argument injection via OCI image label YAML in Docker MCP Gateway

Quick assessment

Affected
docker mcp-gateway
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MCP Gateway 允许轻松且安全地运行和部署 MCP 服务器。在 0.21.0 至 0.42.2 版本中,Docker MCP Gateway 在 和 中,将攻击者可控的 OCI 镜像标签通过 YAML 反序列化(unmarshal)为通用的 结构体,适用于直接的 引用和目录快照导入场景。随后,诸如 、 和 等运行时塑造字段被直接追加到 的参数向量中,而未实施来源白名单(origin allowlist)校验。这使得恶意镜像作者能够在受害者选择或拉取该镜像时,请求挂载主机文件系统或 Docker 套接字(so

CVSS 8.7 · High

Possible ATT&CK Techniques 1 AI

T1578 · Modify Cloud Compute Infrastructure

Affected Version Matrix 1

VendorProduct Version RangeStatus
docker mcp-gateway >= 0.21.0, < 0.42.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55887

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MCP Gateway: Argument injection via OCI image label YAML in Docker MCP Gateway
Source: CVE Program / CVE List V5
Vulnerability Description
MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server structure for direct docker:// references and catalog snapshot imports in pkg/oci/self_contained.go and pkg/workingset/workingset.go. Runtime-shaping fields including Volumes, User, and ExtraHosts were then appended to the docker run argument vector without an origin allowlist, allowing a malicious image author to request host filesystem or Docker socket mounts and UID 0 execution when a victim selected or pulled the image. This container-creation-time boundary bypass can execute arbitrary code on the host and is not prevented by no-new-privileges because no in-container privilege escalation is required. This issue is fixed in version 0.42.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
参数注入或修改
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
docker mcp-gateway >= 0.21.0, < 0.42.2 -

II. Public POCs for CVE-2026-55887

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55887

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55887 (1)

Vendor Advisories for CVE-2026-55887 (1)

Vendor Pages for CVE-2026-55887 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-55887

No comments yet


Leave a comment