Flaw Exposes Docker Desktop Users to Code Execution and Data Theft
Article excerpt
Highlighted: the sentence this signal was extracted from
Flaw exposes Docker Desktop users to code execution and data theft. Cybersecurity researchers have disclosed details of a now-patched security flaw impacting Ask Gordon, an artificial intelligence (AI) assistant built into Docker Desktop and the Docker Command-Line Interface (CLI). Notably, attackers could exploit the issue to execute arbitrary code and exfiltrate sensitive data. Security firm Noma Labs has codenamed the critical vulnerability DockerDash. In response, Docker addressed the issue with the release of version 4.50.0 in November 2025. "In DockerDash, a single malicious metadata label in a Docker image can be used to compromise your Docker environment through a simple three-stage attack: Gordon AI reads and interprets the malicious instruction, forwards it to the MCP [Model Context Protocol] Gateway, which then executes it through MCP tools," Sasi Levi, security research lead at Noma, said in a report shared with The Hacker News. "Every stage happens with zero validation, taking advantage of current agents and MCP Gateway architecture." As a result, successful exploitation can trigger critical-impact remote code execution on cloud and CLI systems or enable high-impact data exfiltration on desktop applications. According to Noma Security, the issue originates from Ask Gordon's treatment of unverified metadata as executable commands. Consequently, malicious...
Keep reading with a free account
The rest of this article, and every signal for Docker, is in your free account.
