CVE-2026-5843PoC(apple / docker_desktop)

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple docker_desktop systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Python file, MLX-LM uses importlib to load and execute it with no trust_remote_code gate or equivalent safety check. The MLX backend runs without sandboxing, resulting in arbitrary code execution on the Docker host as the Docker Desktop user. Any container on the Docker network can trigger this by calling the model-runner.docker.internal API to pull a malicious model from an attacker-controlled OCI registry and request inference.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • docker_desktop
  • macos

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-22); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
docker_desktopmacos

1 version affected across 2 products

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-05-22: 2Mentions · 2026-05-23: 2Mentions · 2026-09-17: 1PoC Mentioned / Linked · 2026-05-22: 2Patch / Workaround · 2026-09-17: 1Technical Details · 2026-05-23: 2Technical Details · 2026-09-17: 105-2205-2309-17
Signal classification3 categories
PoC
240.0%
Disclosure
240.0%
Patch
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-222
PoC2
2026-05-232
Disclosure2
2026-09-171
Patch1
Full discourse5 posts
  • Threat Landscape@LandscapeThreat
    Patch

    Docker disclosed two Docker Sandboxes vulnerabilities that can allow malicious guest environments to escape workspace isolation and access host resources. CVE-2026-77179, affecting macOS versions before 0.42.0, enables symlink-race redirection of filesystem operations, potentially permitting arbitrary file read/write and host code execution. CVE-2026-79994, affecting versions before 0.42.0, can redirect guest-to-host Unix socket connections to unauthorized AF_UNIX sockets, enabling data disclosure or access to host-side functions. Docker recommends upgrading to 0.42.0 or later, using clone mode, removing writable host mounts, and minimizing sensitive data in shared paths. VULNERABILITY CVE-2026-17106 CVE-2026-2664 CVE-2026-28400 CVE-2026-33990 CVE-2026-5817 CVE-2026-5843 CVE-2026-77179 CVE-2026-79994

    Post summary

    Docker disclosed two sandbox escape vulnerabilities (CVE-2026-77179 and CVE-2026-79994) with technical details and recommended upgrading to version 0.42.0 or later as a remediation.

    2004173
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5843 The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model director… https://www.cve.org/CVERecord?id=CVE-2026-5843

    Post summary

    CVE-2026-5843 exposes that Docker Model Runner’s MLX inference backend on macOS can unconditionally import and execute arbitrary Python files via the MLX-LM library, enabling potential code execution.

    01010243
    57.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5843 The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model director… https://www.cve.org/CVERecord?id=CVE-2026-5843 ----- Traducción: CVE-2026-5843 El … http://infoflow.cloud`

    Post summary

    A fresh CVE (CVE‑2026‑5843) is reported, noting that the Docker Model Runner's MLX inference backend can unconditionally import and execute arbitrary Python files, presenting a code‑execution risk.

    0001055
    79 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    PoC

    CVE-2026-5843 CVE-2026-5843 PoC Minimal OCI registry that serves a malic... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5843 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces a Proof of Concept for CVE-2026-5843 and shares a link to more information, but offers no further technical details, exploit code, or patch information.

    0000097
    4.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    PoC

    CVE-2026-5817 CVE-2026-5843 PoC Minimal OCI registry that serves a malicious model to e... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5817 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post references CVE-2026-5843 as having a Proof of Concept involving a minimal OCI registry that serves a malicious model, and provides a link to vulnerability details for CVE-2026-5817, but it offers no exploit code, patch information, or evidence of active exploitation.

    0000091
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appdockerdocker_desktop---

Explore more