A critical-severity vulnerability, named DockerDash, in Docker's Ask Gordon AI assistant allows for Remote Code Execution (RCE) in Docker environments. This is achieved through "meta-context injection," where malicious instructions embedded in Docker image metadata labels are executed by the Model Context Protocol (MCP) Gateway without proper validation.
Why This Matters
The evidence matters to defenders using Meta because it could let an attacker run code in affected environments.
Recommended Action
Confirm whether rce is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.
Affected
DockerMetaAsk Gordon AI assistantDocker environmentsDocker image metadata labelsModel Context Protocol (MCP) Gateway