PT-2025-20705 · Toolhive · Toolhive

Dmjb

·

Published

2025-05-12

·

Updated

2025-05-12

·

CVE-2025-47274

CVSS v4.0

2.4

Low

VectorAV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ToolHive versions prior to 0.0.33
Description The issue arises from the ordering of code used to start a Model Context Protocol (MCP) server container in ToolHive, inadvertently storing secrets in run config files. This allows an attacker with access to the user's home folder to read secrets without needing access to the secrets store itself. The issue only applies to secrets used in containers with existing run configs.
Recommendations For versions prior to 0.0.33, stop and delete any running MCP servers. For versions prior to 0.0.33, manually remove any runconfigs from $HOME/Library/Application Support/toolhive/runconfigs/ (macOS) or $HOME/.state/toolhive/runconfigs/ (Linux). Update to version 0.0.33 to fix the issue.

Exploit

Fix

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2025-47274
GHSA-XJ5P-W2V5-FJM6

Affected Products

Toolhive