Skip to main content
DockerLaunch

Flaw Exposes Docker Desktop Users to Code Execution and Data Theft

What happened

Docker, Inc. launched version 4.50.0 on Nov 1st '25.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

Flaw exposes Docker Desktop users to code execution and data theft. Cybersecurity researchers have disclosed details of a now-patched security flaw impacting Ask Gordon, an artificial intelligence (AI) assistant built into Docker Desktop and the Docker Command-Line Interface (CLI). Notably, attackers could exploit the issue to execute arbitrary code and exfiltrate sensitive data. Security firm Noma Labs has codenamed the critical vulnerability DockerDash. In response, Docker addressed the issue with the release of version 4.50.0 in November 2025. "In DockerDash, a single malicious metadata label in a Docker image can be used to compromise your Docker environment through a simple three-stage attack: Gordon AI reads and interprets the malicious instruction, forwards it to the MCP [Model Context Protocol] Gateway, which then executes it through MCP tools," Sasi Levi, security research lead at Noma, said in a report shared with The Hacker News. "Every stage happens with zero validation, taking advantage of current agents and MCP Gateway architecture." As a result, successful exploitation can trigger critical-impact remote code execution on cloud and CLI systems or enable high-impact data exfiltration on desktop applications. According to Noma Security, the issue originates from Ask Gordon's treatment of unverified metadata as executable commands. Consequently, malicious...

Keep reading with a free account

The rest of this article, and every signal for Docker, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Launch

What this signalsA launch often needs new go-to-market and support spend.

Takes effect
Nov 1, 2025

The full record

From the Signal API record

Details

Release type
Version 4.50.0
Category
Launches

Extraction

Confidence
83%
Detected
Feb 3, 2026
signal_type
news
signal_subtype
launches

Use this data

Get every launch signal for Docker and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Docker this week?”

  2. Send it to your own tools

    The Signal API returns launch signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/83cbb489-2c28-4bc5-a526-ca8ff04f8578 returns this record as JSON. POST /v1/companies/enrich returns every signal for docker.com.

{
  "signal_id": "83cbb489-2c28-4bc5-a526-ca8ff04f8578",
  "signal_type": "news",
  "signal_subtype": "launches",
  "detected_at": "2026-02-03T19:14:26+00:00",
  "company": {
    "name": "Docker",
    "domain": "docker.com"
  },
  "data": {
    "url": "https://impreza.host/flaw-exposes-docker-desktop-users-to-code-execution-and-data-theft",
    "title": "Flaw Exposes Docker Desktop Users to Code Execution and Data Theft",
    "excerpt": "Flaw exposes Docker Desktop users to code execution and data theft.\n\nCybersecurity researchers have disclosed details of a now-patched security flaw impacting Ask Gordon, an artificial intelligence (AI) assistant built into Docker Desktop and the Docker Command-Line Interface (CLI). Notably, attackers could exploit the issue to execute arbitrary code and exfiltrate sensitive data.\n\nSecurity firm Noma Labs has codenamed the critical vulnerability DockerDash. In response, Docker addressed the issue with the release of version 4.50.0 in November 2025.\n\n\"In DockerDash, a single malicious metadata label in a Docker image can be used to compromise your Docker environment through a simple three-stage attack: Gordon AI reads and interprets the malicious instruction, forwards it to the MCP [Model Context Protocol] Gateway, which then executes it through MCP tools,\" Sasi Levi, security research lead at Noma, said in a report shared with The Hacker News.\n\n\"Every stage happens with zero validation, taking advantage of current agents and MCP Gateway architecture.\"\n\nAs a result, successful exploitation can trigger critical-impact remote code execution on cloud and CLI systems or enable high-impact data exfiltration on desktop applications.\n\nAccording to Noma Security, the issue originates from Ask Gordon's treatment of unverified metadata as executable commands. Consequently, malicious...",
    "product": "version 4.50.0",
    "summary": "Docker, Inc. launched version 4.50.0 on Nov 1st '25.",
    "category": "launches",
    "found_at": "2026-02-03T19:14:26Z",
    "planning": false,
    "image_url": "https://impreza.host/wp-content/uploads/2021/09/vulnerabilidade-xss-ataque-attack-hackers.jpg",
    "confidence": 0.8288,
    "product_data": {
      "full_text": "version 4.50.0",
      "fuzzy_match": true,
      "release_type": "version 4.50.0",
      "release_version": "4.50.0"
    },
    "published_at": "2026-02-03T19:14:26Z",
    "effective_date": "2025-11-01",
    "article_sentence": "In response, Docker addressed the issue with the release of version 4.50.0 in November 2025."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.