Remote Authentication Bypass in ToolHive by Stacklok
CVE-2026-58196
4.7MEDIUM
What is CVE-2026-58196?
ToolHive, a utility for managing Model Context Protocol (MCP) servers, has a vulnerability where remote authentication mechanisms are not securely configured prior to version 0.31.0. The application trusts remote-server-controlled authentication discovery destinations, which enables a malicious remote MCP server to manipulate authentication URLs and potentially access internal services. Specifically, the flawed authentication process can lead to unauthorized access to link-local or private network services, such as retrieving sensitive AWS metadata credentials, through improper host and scheme handling. This critical security issue has been addressed in the updated version 0.31.0.
Affected Version(s)
toolhive < 0.31.0
