Impact
The vulnerability is a server‑side request forgery that exploits a DNS Time‑of‑Check to Time‑of‑Use race during tool invocation in IBM ContextForge MCP Gateway versions up to and including 1.0.6. An attacker who can authenticate and create a tool can supply a controlled hostname that rebinding DNS to an internal address, causing the gateway to resolve that hostname and potentially obtain sensitive data. The weakness is classified as CWE‑918 and results in disclosure of confidential information to the authenticated attacker.
Affected Systems
IBM ContextForge MCP Gateway, versions 1.0.6 and earlier, are affected. Only the gateway component is impacted; other IBM ContextForge products are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity impact. EPSS data is not available, so the likelihood of exploitation cannot be quantified but the lack of a KEV listing suggests no widespread public exploitation yet. The attack requires authentication and the ability to create a tool, but because the gateway performs DNS resolution on the supplied hostname, an adversary can surf the internal network or exfiltrate data. In environments where least‑privilege access controls are enforced, limiting tool‑creation permissions reduces the attacker’s ability to stage the vulnerability but does not eliminate it.
OpenCVE Enrichment