logo

Docker Fixes ‘Ask Gordon’ AI Flaw That Enabled Metadata-Based Attacks

ID: 55facf51-f5b6-5acf-9fad-fe1ddd627978

STIX ID: report--55facf51-f5b6-5acf-9fad-fe1ddd627978

Feed Name: HackRead

Threat Score
70/100

Date Published: 2025-12-19

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive Summary:** Docker Desktop's AI assistant 'Ask Gordon' was found vulnerable to indirect prompt injection via metadata poisoning on Docker Hub, enabling malicious package metadata to cause the assistant to read and exfiltrate sensitive information (build logs, API keys, internal network details); researchers demonstrated the issue and Docker remedied it in version 4.50.0 by requiring explicit user approval before following external instructions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.