Network Utility Vulnerability in ToolHive by StackLok
CVE-2026-54450
What is CVE-2026-54450?
ToolHive, a utility for managing Model Context Protocol (MCP) servers, has a vulnerability in its networking configuration that fails to recognize certain IPv6 NAT64 prefixes as private. This flaw allows an attacker to exploit classifications of private IP addresses as public, creating a pathway for probing internal TCP or TLS connections. The vulnerability specifically arises when an external OAuth client sends a malicious client_id URL, triggering processes that inadvertently allow routing through unsecured paths. Users of ToolHive behind a NAT64/DNS64 gateway are particularly at risk as it can lead to unauthorized internal reachability exploration. The issue has been resolved in version 0.29.1, emphasizing the importance of keeping software updated.
Affected Version(s)
toolhive < 0.29.1
