HomeSecurityDocker fixes critical flaw in Ask Gordon AI

Docker fixes critical flaw in Ask Gordon AI

Cybersecurity researchers have revealed details of a now-patched security flaw affecting Ask Gordon, an artificial intelligence (AI) assistant built into Docker Desktop and the Docker command-line interface (CLI), that could be exploited to execute code and extract sensitive data.

See also: Docker Desktop Windows: Vulnerability leads to system compromise

Docker Ask Gordon

The critical vulnerability has been codenamed DockerDash by cybersecurity firm Noma Labs. It was addressed by Docker with the release of version 4.50.0 in November 2025.

“In DockerDash, a simple malicious metadata tag in a Docker image can be used to compromise your Docker environment through a simple three-stage attack: Gordon AI reads and interprets the malicious command, forwards it to the MCP [Model Context Protocol] Gateway, which then executes it via MCP tools,” said Sasi Levi, head of security research at Noma, in a report shared with The Hacker News. “Each stage occurs without any validation, exploiting the current agents and architecture of the MCP Gateway.”

Successful exploitation of the vulnerability could lead to remote code execution with critical impact for cloud and CLI systems or high-impact data extraction for desktop applications.

The problem, according to Noma Security, arises from the fact that the AI ​​assistant treats unverified metadata as executable commands, allowing it to propagate through different layers without any validation, allowing an attacker to bypass security boundaries. The result is that a simple AI question opens the door to executing tools.

With the MCP Gateway acting as a connective tissue between a large language model (LLM) and the local environment, the issue is a failure of trust in the context. The problem has been characterized as a case of Meta-Context Injection.

In a hypothetical attack scenario, a malicious actor could exploit a critical trust boundary violation in the way Ask Gordon parses container metadata. To accomplish this, the attacker creates a malicious Docker image with embedded commands in the Dockerfile tag fields.

See also: Hackers steal crypto via misconfigured Docker APIs

Docker fixes critical flaw in Ask Gordon AI

While metadata fields may seem innocent, they become injection vectors when processed by Ask Gordon AI. The code execution attack chain is as follows:

  1. The attacker publishes a Docker image that contains weaponized tag commands in the Dockerfile.
  2. When a victim asks Ask Gordon AI about the image, Gordon reads the image metadata, including all LABEL fields , exploiting Ask Gordon's inability to distinguish between legitimate metadata descriptions and embedded malicious commands.
  3. Ask Gordon forwards the parsed commands to the MCP gateway, an intermediate layer that sits between the AI ​​agents and the MCP servers.
  4. The MCP Gateway interprets this as a standard request from a trusted source and calls the specified MCP tools without any additional validation.
  5. The MCP tool executes the command with the victim's Docker privileges, achieving code execution.

The data extraction vulnerability exploits the same prompt injection weakness but targets Ask Gordon's Docker Desktop implementation to capture sensitive internal data about the victim's environment using MCP tools, taking advantage of the helper's read-only permissions.

The information collected can include details about installed tools, container details, Docker configuration, connected directories, and network topology.

See also: New self-propagating malware infects Docker Containers

Docker fixes critical flaw in Ask Gordon AI

It is worth noting that the Ask Gordon 4.50.0 also resolves a prompt injection vulnerability discovered by Pillar Security, which could allow attackers to hijack the assistant and extract sensitive data by modifying the Docker Hub repository metadata with malicious commands.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS