Impact
An authenticated user can send a specially crafted request to IBM ContextForge MCP Gateway that contains nested payloads. The gateway’s filtering plugins do not fully traverse these nested structures, which allows the attacker to bypass the regex_filter and deny_filter protection mechanisms. This flaw gives the attacker the ability to inject malicious content that normally would be blocked, potentially exposing confidential data and enabling further intrusion or unauthorized actions within the system.
Affected Systems
IBM ContextForge MCP Gateway versions up to and including 1.0.4 are vulnerable. The fix is available in version 1.0.5 and later. Users with affected versions should plan an upgrade. If upgrade is delayed, administrators should consider disabling the regex_filter and deny_filter plugins in plugins/config.yaml to reduce exploitation risk.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity vulnerability. No EPSS score is available, so the current exploitation probability is unknown. The flaw is not listed in CISA’s KEV catalog. The attack requires authenticated access to the gateway, so the threat vector is likely internal or requires privileged credentials. An attacker who can log in could exploit the bypass to introduce malicious payloads that bypass filtering, potentially compromising system integrity and confidentiality.
OpenCVE Enrichment