IBM Contextforge Mcp Gateway
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM Contextforge Mcp Gateway.
By the Year
In 2026 there have been 6 vulnerabilities in IBM Contextforge Mcp Gateway with an average score of 7.5 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 6 | 7.47 |
It may take a day or so for new Contextforge Mcp Gateway vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Contextforge Mcp Gateway Security Vulnerabilities
IBM ContextForge MCP Gateway 1.0.0-1.0.8 Path Traversal in Admin API log-download
CVE-2026-77825
4.9 - Medium
- September 24, 2026
IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.
Directory traversal
IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could
CVE-2026-11918
5.4 - Medium
- September 15, 2026
IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content.
Denylist / Deny List
IBM ContextForge MCP Gateway 1.0.0-1.0.7 Default Credentials Remote Admin Access
CVE-2026-78573
9.8 - Critical
- September 10, 2026
IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.
1392
CVE-2026-18486: IBM ContextForge MCP Gateway <=1.0.7 jq Filter Credential Theft
CVE-2026-18486
8.8 - High
- September 04, 2026
IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.
Information Disclosure
IBM ContextForge MCP Gateway <=1.0.6 DNS Rebinding Remote Auth Info Disclosure
CVE-2026-18905
7.7 - High
- September 04, 2026
IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.
SSRF
IBM ContextForge MCP Gateway SSRF via DNS Rebinding Remote Auth Info Disclosure
CVE-2026-77822
8.2 - High
- September 04, 2026
IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.
SSRF
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Contextforge Mcp Gateway or by IBM? Click the Watch button to subscribe.