Impact
Prior to version 1.0.3, the /admin/gateways/test endpoint in IBM ContextForge performs DNS resolution during input validation but later performs an unbound look‑up before establishing the transport connection. This Time‑of‑Check to Time‑of‑Use race allows an attacker to supply a DNS name that resolves to a public address during validation and to a private or cloud‑metadata address at connection time, thereby bypassing the SSRF controls that were applied only to the validation result. The result is an internal or cloud‑metadata request originating from the gateway that can steal credentials or probe the internal network.
Affected Systems
IBM ContextForge gateway (mcp-context-forge, mcp-contextforge-gateway) running any version earlier than 1.0.3, when the MCPGATEWAY_ADMIN_API_ENABLED flag is set to true and the attacker can manipulate a database record that grants gateways.read permissions. The vulnerable endpoint resides in mcpgateway/admin.py and uses validate_gateway_test_url() from common/validators.py, with the ResilientHttpClient performing a second resolution.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.6, indicating a medium impact, and an EPSS score of < 1%, suggesting a low likelihood of exploitation. It is not listed in CISA KEV. Likely attack scenarios involve DNS rebinding or injection of malicious gateway entries via a privileged database role, and require network connectivity to the gateway, an enabled admin API, and the ability to alter gateway configurations. Once those prerequisites are met, the race condition enables an attacker to reach internal hosts or metadata services and potentially exfiltrate secrets or further pivot within the host network.
OpenCVE Enrichment
Github GHSA