Impact
IBM ContextForge MCP Gateway versions 1.0.7 and earlier allow a remote authenticated attacker to provide malicious jq filters that are improperly validated. The vulnerability enables the attacker to retrieve sensitive credentials such as JWT_SECRET_KEY, AUTH_ENCRYPTION_SECRET, DATABASE_URL, REDIS_URL, and BASIC_AUTH_PASSWORD, and to elevate privileges within the gateway. This flaw falls under Information Exposure (CWE-200) and constitutes both credential disclosure and privilege escalation.
Affected Systems
The affected product is IBM ContextForge MCP Gateway, specifically any deployment running version 1.0.7 or earlier. Users of these versions should verify their build against the listed version range.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high impact. EPSS is not available, so the precise exploitation probability is unknown, and the vulnerability is not listed in CISA KEV. Attackers would need authenticated access to the gateway and would likely exploit the flaw by submitting crafted jq filters through the gateway's API. Based on the description, the likely attack vector is remote authenticated, which limits exposure to users with valid credentials but still poses a significant risk once those credentials are compromised.
OpenCVE Enrichment