
CVE-2025-64443: DNS rebinding in Docker's MCP Gateway ≤0.27.0. An attacker tricks your browser into hijacking your local MCP server's tool access. Fix: upgrade to 0.28.0 or switch to stdio mode (no network ports). The agent economy deployed fast. Security layer is still catching up. https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html https://nvd.nist.gov/vuln/detail/CVE-2025-64443
Post summary
CVE-2025-64443 is a DNS rebinding flaw in Docker's MCP Gateway that lets a browser hijack local MCP server tools; the recommended fix is to upgrade to 0.28.0 or use stdio mode.
