{"id":"CVE-2026-55887","aliases":["GHSA-r2xf-7jw5-pjg6","GO-2026-5604"],"url":"https://o3.security/vulnerability/CVE-2026-55887","summary":"MCP Gateway: Argument injection via OCI image label YAML in Docker MCP Gateway","details":"MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server structure for direct docker:// references and catalog snapshot imports in pkg/oci/self_contained.go and pkg/workingset/workingset.go. Runtime-shaping fields including Volumes, User, and ExtraHosts were then appended to the docker run argument vector without an origin allowlist, allowing a malicious image author to request host filesystem or Docker socket mounts and UID 0 execution when a victim selected or pulled the image. This container-creation-time boundary bypass can execute arbitrary code on the host and is not prevented by no-new-privileges because no in-container privilege escalation is required. This issue is fixed in version 0.42.2.","published":"2026-09-15T15:45:36.420Z","modified":"2026-09-16T03:47:04.720266983Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/docker/mcp-gateway","fixedVersion":"0.42.2"}],"fix":{"url":"https://github.com/docker/mcp-gateway/commit/306d2d94a3b526f43281313321bf784f2d46a7fe","label":"docker/mcp-gateway@306d2d9"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55887.json"},{"type":"FIX","url":"https://github.com/docker/mcp-gateway/commit/306d2d94a3b526f43281313321bf784f2d46a7fe"},{"type":"FIX","url":"https://github.com/docker/mcp-gateway/commit/439b2200d9e26a4ff414aeb043785df45a78422b"},{"type":"FIX","url":"https://github.com/docker/mcp-gateway/pull/498"},{"type":"WEB","url":"https://github.com/docker/mcp-gateway/releases/tag/v0.42.2"},{"type":"ADVISORY","url":"https://github.com/docker/mcp-gateway/security/advisories/GHSA-r2xf-7jw5-pjg6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55887"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T03:47:04.720266983Z"}}