CVE-2026-5817 is an arbitrary code execution vulnerability in the vllm-metal inference backend used by Docker Model Runner on macOS. The backend unconditionally enables remote code trust when loading model tokenizers, causing tokenizer loading through transformers.AutoTokenizer.from_pretrained() to import and execute Python code packaged inside a model obtained from an OCI registry. Because the affected backend runs without sandboxing, attacker-controlled code embedded in a malicious model can execute on the Docker host in the security context of the Docker Desktop user when inference is invoked. The issue can be triggered indirectly from a container on the Docker network through the model runner API by causing the service to pull a malicious model and perform inference.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Single-file Python proof-of-concept exploit for CVE-2026-5817 targeting Docker Desktop <= 4.67.x on Apple Silicon, specifically the Docker Model Runner / vllm-metal path. The script implements a minimal attacker-controlled OCI/Docker registry over HTTP on port 5555 and serves a crafted model package containing: (1) a minimal safetensors model, (2) Hugging Face-style config.json, (3) tokenizer_config.json with auto_map pointing AutoTokenizer to evil_tokenizer.EvilTokenizer, and (4) evil_tokenizer.py containing attacker-controlled Python. The intended exploitation flow is: run the registry on the host, use a container to call model-runner.docker.internal/api/pull with model reference host.docker.internal:5555/evil/model:latest, then invoke the chat completions endpoint to force model loading. When the target loads the tokenizer with trust_remote_code behavior, the malicious Python executes on the host, demonstrating container-to-host RCE. The included payload is a benign proof that writes host/user/id/timestamp data to ~/Desktop/vllm.txt. Repository structure is minimal: one standalone Python script with embedded payload, OCI manifest/blob generation logic, and an HTTP handler implementing /v2, manifest, and blob routes.
This repository is a working proof-of-concept exploit for CVE-2026-5817, demonstrating container-to-host code execution against Docker Desktop Model Runner. The exploit chain is: an unprivileged container reaches model-runner.docker.internal without authentication, asks Model Runner to pull a model from an attacker-controlled OCI registry, then triggers inference so a Python backend loads the model with trust_remote_code enabled. The malicious model’s tokenizer_config.json points AutoTokenizer to evil_tokenizer.py, whose module-level code executes on the host. Repository structure: README.md explains the vulnerability, prerequisites, and attack flow. rce_registry.py is the core exploit component: a custom Python HTTP server implementing a minimal malicious OCI registry that serves a valid-looking model bundle, tokenizer_config.json, and the embedded evil_tokenizer.py payload. It also exposes several /_poc/* introspection endpoints for health and self-test. run_poc.sh is the main operator wrapper that checks prerequisites, starts the registry with docker compose, launches the attack from an unprivileged curl container, and checks for proof artifacts. docker-compose.yml defines two services: the malicious registry and the attacker container that performs the two key POST requests to Model Runner. Dockerfile.registry and Dockerfile.attacker build the helper containers. test_claims.py is a validation harness that performs static and runtime checks against the upstream Model Runner codebase and the local PoC environment; it is auxiliary validation logic, not the exploit itself. Main exploit capabilities: (1) stand up a malicious OCI registry serving a crafted model, (2) induce Model Runner to pull and store that model, (3) trigger host-side import and execution of attacker-controlled Python code, and (4) demonstrate post-escape impact by checking host filesystem access, Docker socket access, Docker daemon enumeration, and Docker credential file visibility. The payload is basic but real and hardcoded, making the exploit operational rather than merely illustrative.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.