logo

DockerDash Exposes AI Supply Chain Weakness In Docker's Ask Gordon

ID: 73f17290-25ad-57d9-9973-8e750d334f98

STIX ID: report--73f17290-25ad-57d9-9973-8e750d334f98

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

...
...

Noma Labs disclosed "DockerDash," a critical AI-supply-chain vulnerability in Docker's Ask Gordon assistant where malicious Docker LABEL metadata is interpreted as instructions (Meta-Context Injection), enabling RCE in cloud/CLI environments and data exfiltration/reconnaissance in Docker Desktop; Docker issued mitigations and patched Docker Desktop 4.50.0, and users are urged to update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.