Impact
The python_sandbox_server component of IBM MCP Context Forge exposes the built‑in getattr function through safe_builtins without the required _getattr_ guard and relies on validate_code checks that only block literal dangerous dunder strings. An attacker can construct arbitrary dunder names at runtime, navigate the Python class hierarchy, and eventually access subprocess.Popen, allowing the execution of operating‑system commands with the same privileges as the server process. The execute_code MCP tool is delivered over HTTP/SSE, and when the transport is exposed without authentication, an attacker can trigger this flaw from any network location that can reach the end‑point. The vulnerability results in full remote code execution on the host running the python_sandbox_server and has a CVSS score of 10, an EPSS score of < 1%, and is not yet listed in CISA’s KEV catalog.
Affected Systems
The vulnerability impacts IBM MCP Context Forge—specifically the python_sandbox_server subproject in the MCP‑Servers bundle. All releases earlier than 1.0.2 are affected, regardless of deployment mode. The core Context Forge gateway and proxy components are not directly impacted, but the sandbox component serves as a potential foothold within the overall platform.
Risk and Exploitability
With a CVSS score of 10, the issue is classified as Critical. Although the EPSS score is low (< 1%), the fact that the execute_code tool can be accessed via unauthenticated HTTP/SSE or via local stdio‑only deployments means that remote or local attackers can exploit the flaw provided they have network reach to the server. The vulnerability is not currently listed in CISA’s KEV catalog, yet operators should prioritize remediation due to the severity and the lack of built‑in authentication for the exposed service.
OpenCVE Enrichment
Github GHSA