Impact
An authenticated user can send a specially crafted request to IBM ContextForge MCP Gateway that contains nested payloads. The gateway’s filtering plugins do not fully traverse to bypass the regex_filter and deny_filter protection mechanisms. This flaw is a CWE-184 weakness and gives the attacker the ability to inject malicious content that and enabling further intrusion or unauthorized actions within the system.
Affected Systems
IBM ContextForge MCP Gateway versions up to and including 1.0.4 are vulnerable. The fix is available in version 1.0.5 and later. Users with affected versions should plan an upgrade. If upgrade is delayed, administrators should consider disabling the regex_filter and deny_filter plugins in plugins/config.yaml to reduce exploitation risk.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity vulnerability. The EPSS score is < 1%, indicating only a very low exploitation probability. The flaw is not listed in CISA’s KEV catalog. An attacker needs authenticated access to the gateway, so the attack vector is likely internal or requires privileged credentials. An authenticated attacker could exploit the bypass to introduce malicious payloads that bypass filtering, potentially compromising system integrity and confidentiality.
OpenCVE Enrichment