Remote Authentication Bypass in ToolHive by Stacklok
CVE-2026-58196

4.7MEDIUM

Key Information:

Vendor

Stacklok

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-58196?

ToolHive, a utility for managing Model Context Protocol (MCP) servers, has a vulnerability where remote authentication mechanisms are not securely configured prior to version 0.31.0. The application trusts remote-server-controlled authentication discovery destinations, which enables a malicious remote MCP server to manipulate authentication URLs and potentially access internal services. Specifically, the flawed authentication process can lead to unauthorized access to link-local or private network services, such as retrieving sensitive AWS metadata credentials, through improper host and scheme handling. This critical security issue has been addressed in the updated version 0.31.0.

Affected Version(s)

toolhive < 0.31.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.