CVE Explorer
CVE-2026-28400
Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 expose a POST `/engines/_configure` endpoint that accepts arbitrary runtime flags without authentication. These flags are passed directly to the underlying inference server (llama.cpp). By injecting the --log-file flag, an attacker with network access to the Model Runner API can write or overwrite arbitrary files accessible to the Model Runner process. When bundled with Dock
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"model-runner","vendor":"docker","versions":[{"status":"affected","version":"< 1.0.16"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ca019d1078be27c9e98b38c12eb6d8379b2eb220fe2968e816d349f64818dd56 · sha256:c1cce59bf6601d99… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.6,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ca019d1078be27c9e98b38c12eb6d8379b2eb220fe2968e816d349f64818dd56 · sha256:c1cce59bf6601d99… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-749","description":"CWE-749: Exposed Dangerous Method or Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ca019d1078be27c9e98b38c12eb6d8379b2eb220fe2968e816d349f64818dd56 · sha256:c1cce59bf6601d99… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/docker/model-runner/security/advisories/GHSA-m456-c56c-hh5c","tags":["x_refsource_CONFIRM"],"url":"https://github.com/docker/model-runner/security/advisories/GHSA-m456-c56c-hh5c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ca019d1078be27c9e98b38c12eb6d8379b2eb220fe2968e816d349f64818dd56 · sha256:c1cce59bf6601d99… · /containers/cna/references/0
{"name":"https://www.zerodayinitiative.com/advisories/ZDI-CAN-28379","tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-CAN-28379"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ca019d1078be27c9e98b38c12eb6d8379b2eb220fe2968e816d349f64818dd56 · sha256:c1cce59bf6601d99… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.