Docker Model Runner是Docker开源的一个Docker模型运行器。 Docker Model Runner MLX存在安全漏洞,该漏洞源于无条件导入并执行模型目录中的任意Python文件,可能导致从攻击者控制的OCI注册表拉取恶意模型并请求推理时,在Docker主机上执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Docker | Docker Desktop | 4.56.0< 4.71.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Docker | Docker Desktop | 4.56.0 ~ 4.71.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6406 | 8.8 HIGH | Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag |
| CVE-2026-5817 | 8.2 HIGH | Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in |
No comments yet