Impact
The vulnerability arises from cross‑client credential context confusion in the IBM ContextForge MCP Gateway Translate utility. Because the service was designed only for local, single‑session development, it does not isolate session data for multiple concurrent clients. An attacker can exploit this lack of isolation to read sensitive information that belongs to other sessions. The resulting impact is information disclosure from one client to another.
Affected Systems
The IBM ContextForge MCP Gateway – Translate utility is affected, with all releases up to and including version 1.0.8. The vulnerability exists in these releases; it should be mitigated by ensuring the service is not deployed in a production or multi‑client environment.
Risk and Exploitability
The CVSS score of 7.4 classifies the vulnerability as high severity, and it can be exploited remotely against an exposed Translate service. The EPSS score is unavailable, and the issue is not listed in CISA KEV, but if the Translate service resides on an unprotected network a remote attacker could send crafted requests to obtain data from other sessions. The likelihood of exploitation depends on whether an organization has deployed the service outside its intended local development context.
OpenCVE Enrichment