Missing Authorization in MCP Gateway - #VU139379
Published: July 26, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the host.
The vulnerability exists due to missing authorization in the dynamic management tools and container volume handling when supplying crafted configuration to dynamic tools. A remote user can provide a sensitive host path as a bind mount value to execute arbitrary code on the host.
Exploitation requires dynamic tools to be enabled and the gateway to have Docker API authority.