CVE-2026-5817Disclosure(apple / docker_desktop)

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple docker_desktop systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and execute arbitrary Python files included in any model pulled from an OCI registry, resulting in arbitrary code execution on the Docker host as the Docker Desktop user when inference is triggered. Any container on the Docker network can trigger this by calling the model-runner.docker.internal API to pull a malicious model and request inference.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • docker_desktop
  • macos

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-23); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
docker_desktopmacos

1 version affected across 2 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-22: 1Mentions · 2026-05-23: 2Mentions · 2026-05-25: 1Mentions · 2026-09-17: 1PoC Mentioned / Linked · 2026-05-22: 1Patch / Workaround · 2026-09-17: 1Technical Details · 2026-05-23: 2Technical Details · 2026-05-25: 1Technical Details · 2026-09-17: 105-2205-2305-2509-17
Signal classification3 categories
Disclosure
360.0%
PoC
120.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-221
PoC1
2026-05-232
Disclosure2
2026-05-251
Disclosure1
2026-09-171
Patch1
Full discourse5 posts
  • Threat Landscape@LandscapeThreat
    Patch

    Docker disclosed two Docker Sandboxes vulnerabilities that can allow malicious guest environments to escape workspace isolation and access host resources. CVE-2026-77179, affecting macOS versions before 0.42.0, enables symlink-race redirection of filesystem operations, potentially permitting arbitrary file read/write and host code execution. CVE-2026-79994, affecting versions before 0.42.0, can redirect guest-to-host Unix socket connections to unauthorized AF_UNIX sockets, enabling data disclosure or access to host-side functions. Docker recommends upgrading to 0.42.0 or later, using clone mode, removing writable host mounts, and minimizing sensitive data in shared paths. VULNERABILITY CVE-2026-17106 CVE-2026-2664 CVE-2026-28400 CVE-2026-33990 CVE-2026-5817 CVE-2026-5843 CVE-2026-77179 CVE-2026-79994

    Post summary

    Docker disclosed two sandbox escape vulnerabilities, CVE-2026-77179 and CVE-2026-79994, providing technical details and recommending an upgrade to version 0.42.0 or later along with workarounds.

    2004173
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5817 The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing.… https://www.cve.org/CVERecord?id=CVE-2026-5817

    Post summary

    The note announces CVE-2026-5817, describing how the vllm-metal backend on macOS sets trust_remote_code=True unsafely and lacks sandboxing.

    01010243
    57.5K followersView on X
  • Technology Updates@DIYprojects55
    Disclosure

    https://pbxscience.com/security-advisory-cve-2026-5817-docker-model-runner-arbitrary-code-execution-via-unsandboxed-trust_remote_code-tokenizer-loading/ Security Advisory: CVE-2026-5817 — Docker Model Runner Arbitrary Code Execution via Unsandboxed trust_remote_code Tokenizer Loading Docker has officially disclosed CVE-2026-5817, a high-severity code execution vulnerability in the Docker Model Runner's..

    Post summary

    This advisory announces Docker’s official disclosure of CVE‑2026‑5817, a high‑severity code‑execution flaw in the Docker Model Runner associated with unsandboxed trust_remote_code tokenizer loading.

    0000069
    558 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5817 The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing.… https://www.cve.org/CVERecord?id=CVE-2026-5817 ----- Traducción: CVE-2026-5817 El … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-5817, noting that the vllm‑metal inference backend on macOS improperly sets trust_remote_code=True and lacks sandboxing, thereby exposing the system to potential unsafe model loading.

    0000043
    79 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    PoC

    CVE-2026-5817 CVE-2026-5843 PoC Minimal OCI registry that serves a malicious model to e... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5817 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet lists CVE-2026-5817 and CVE-2026-5843, highlights the existence of a proof‑of‑concept for the latter, and provides links to vulnerability details and a notification, but does not mention exploitation tools, active attacks, patches, or technical specifics.

    0000091
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appdockerdocker_desktop---

Explore more