Affected by GO-2026-6002
and 1 other vulnerabilities
GO-2026-6002: ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) in github.com/stacklok/toolhive
GO-2026-6526: ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement in github.com/stacklok/toolhive