AI/ML, Vulnerability Management, DevOps

Noma Security discovers flaw in Docker’s AI assistant

Docker logo close-up on website page

Cloud Native reports that Noma Security has uncovered a security vulnerability, dubbed DockerDash, within Docker's AI assistant, Ask Gordon. This flaw allows attackers to compromise the AI assistant through a seemingly simple three-stage attack initiated by a malicious metadata label within a Docker image.

The DockerDash vulnerability exploits a failure in contextual trust, where the Model Context Protocol (MCP) Gateway cannot differentiate between legitimate metadata and malicious instructions. An attacker can embed harmful commands within a Docker image's metadata labels. When Ask Gordon processes these labels, it forwards the instructions to the MCP Gateway, which then executes them using application development tools. This process bypasses human validation, enabling a cybercriminal to gain control of the Docker environment. A related data exfiltration vulnerability leverages the same prompt-injection flaw, allowing attackers to steal sensitive internal data from Docker Desktop's Ask Gordon, even with read-only restrictions.

This discovery highlights a significant risk in the rapid adoption of AI tools by application developers, who often lack a full understanding of the inherent security dangers. With 60% of developers already using AI coding tools and more planning to increase investments, the potential for supply chain compromises is substantial.

Source: Cloud Native

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds