IBM ContextForge MCP Gateway

7 known vulnerabilities in IBM ContextForge MCP Gateway, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-77825 CVSS 4.9 medium IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET…
  • CVE-2026-11918 CVSS 5.4 medium IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to…
  • CVE-2026-78573 CVSS 9.8 critical IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default…
  • CVE-2026-18489 CVSS 7.4 high IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information…
  • CVE-2026-18486 CVSS 8.8 high IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and…
  • CVE-2026-77822 CVSS 9.6 critical IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request…
  • CVE-2026-18905 CVSS 7.7 high IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to…