These capabilities have greater authority than model inference. Registering a process or loading native code can cross directly into the host execution boundary. The vendor distinguishes the published static Docker builds: plugin.Open fails there, while the remote fetch still creates a blind-SSRF concern.
What deployment does this concern?
Component and scope: Reachable management APIs with authentication disabled; stdio MCP registration and remote custom-plugin loading.
Affected versions / scope: Stdio advisory: < 1.5.27. Remote-plugin advisory: < 1.6.3.
Vendor remediation: Both advisories identify 2.1.0.
The management API must be reachable with authentication disabled. Stdio MCP registration can start processes as the service user. The remote-plugin code-execution path additionally requires a dynamically linked build produced with DYNAMIC=1.
Vendor response and practical action
The vendor's 2.1.0 notes corroborate authentication protections for stdio registration and private-address handling for remote plugins. Use the supported patched release, authenticate administration and keep management access separate from model callers.
Treat the vendor notice as the starting point for an applicability decision. Identify the installed artifact and configuration, document whether the prerequisite exists, and assign an owner to any required change. A public advisory does not establish that your installation was exposed or that a managed service shares the same condition.
What clients can learn
An API key that permits inference should not automatically permit plugin installation or process registration. Test administration with the credentials used by an ordinary client, including after a proxy or ingress is added.
A useful evaluation result connects a named control to evidence from the actual deployment. Keep the provider's statement, your effective configuration and a relevant demonstration together. If the result depends on a feature being disabled or a network being isolated, retain that fact with the version number so a later change triggers review.
Questions to take to your provider
- Can an application caller reach MCP registration or plugin installation?
- Is the deployed artifact static or dynamically linked?
- Which identity and filesystem permissions apply to spawned processes?
- Does outbound fetching reject private destinations and redirects?
Use the six-page evaluation worksheet to record evidence, ownership and actions. Continue with AI gateway security: protect the boundaries that matter for the wider evaluation context.
Technical detail: evidence and identifier limits
Two mechanisms are discussed in one case because they share an administrative trust boundary. The remote-plugin RCE finding must not be applied to every static image.
- Version ranges belong to separate advisories; do not combine them into one affected interval.
Evidence label: security advisory. Source-review date: 2026-10-07. Source publication or event date: 2026-09-23. These dates do not change merely because this article is rebuilt.