stacklok has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 4.7 (medium). Most affected products: toolhive (2), github.com/stacklok/toolhive (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.7
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-58197High· 8.8ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers60CVE-2026-58196Medium· 4.7ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers38CVE-2026-54450Low· 2.9ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers16
stacklok vulnerabilities
CVEs affecting stacklok, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-58197High· 8.8PoCToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission pro…
CVE-2026-58196Medium· 4.7PoCToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in pkg/auth/remote/handler.go invokes discovery.DetectAuthenticationFromServer…
CVE-2026-54450Low· 2.9ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in pkg/networking/utilities.go omits the IPv6 NAT64 prefixes 64:ff9b::/96 and 64:ff…