A command injection vulnerability (CVE-2026-5741) has been identified in suvarchal docker-mcp-server versions up to 0.1.0, specifically affecting the stop_container, remove_container, and pull_image functions in the HTTP interface component. The vulnerability allows unauthenticated remote attackers to inject arbitrary OS commands through these functions via the HTTP interface. The affected component processes user-supplied input without sufficient sanitization, creating a direct pathway for command execution on the underlying system. The vulnerability carries a CVSS 3.1 score of 7.3 (HIGH), indicating significant risk. The attack requires no authentication, low complexity, and no user interaction, with the network as the attack vector. Successful exploitation could result in confidentiality, integrity, and availability compromise, potentially granting attackers full system access. The EPSS score of 0.022 indicates below-average predicted likelihood of exploitation compared to other known vulnerabilities. Exploit code has been publicly disclosed, creating a practical exploitation risk. However, the vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows no active exploitation in the wild. The project maintainers were notified early through an issue report but have not yet responded with a patch or mitigation guidance. Organizations using docker-mcp-server should prioritize monitoring for updates and consider implementing network access controls to restrict HTTP interface exposure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Suvarchal | Docker-Mcp-Server | 0.1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.