Security: stacklok/toolhive
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)GHSA-pr64-jmmf-jp54 published
Jun 26, 2026 by rdimitrovModerate -
SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gatewayGHSA-pph6-vfjv-vpjw published
Jun 4, 2026 by rdimitrovLow -
Security: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movementGHSA-qg2g-g9w3-m5h8 published
Jul 28, 2026 by ChrisJBurnsHigh -
Secrets are stored in the state store with no encryptionGHSA-xj5p-w2v5-fjm6 published
May 12, 2025 by dmjbLow