VYPR

ContextForge MCP Gateway

by IBM

CVEs (4)

  • CVE-2026-18486HigSep 4, 2026
    risk 0.57cvss 8.8epss

    IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.

  • CVE-2026-77822HigSep 4, 2026
    risk 0.53cvss 8.2epss

    IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.

  • CVE-2026-18905HigSep 4, 2026
    risk 0.50cvss 7.7epss

    IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.

  • CVE-2026-18489HigSep 4, 2026
    risk 0.41cvss 7.4epss

    IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.