Docker

cat docker.log

Container Escape via Inference: Two Vulnerabilities in Docker Model Runner

CVE-2026-5817 · CVE-2026-5843

Two container-to-host RCE vulnerabilities in Docker. vllm-metal hardcoded trust_remote_code=True, letting a malicious model execute arbitrary Python on the host. When Docker quietly patched it, we found mlx-lm doing the same thing through an importlib path with no gate at all....

May 20, 2026 · 10 min · David Rochester

SSRF and Token Theft in Docker Model Runner

CVE-2026-33990

SSRF in Docker Model Runner’s OCI authentication flow. A malicious registry can redirect the token exchange to scan internal networks and exfiltrate tokens during a model pull....

March 29, 2026 · 8 min · David Rochester