Description
MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a required _getattr_ guard, and relies on validate_code checks for literal dangerous dunder strings. An attacker can construct dunder names at runtime, traverse the Python class hierarchy, reach subprocess.Popen, and execute OS commands with the server process privileges through the execute_code MCP tool. The HTTP/SSE transport can expose this tool without authentication, while stdio-only deployments have reduced network reachability. The issue affects the python_sandbox_server subproject and does not directly affect the core Context Forge gateway or proxy components. This issue is fixed in version 1.0.2.
Published: 2026-09-15
Score: 10 Critical
EPSS: 1.1% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The python_sandbox_server component of IBM MCP Context Forge exposes the built‑in getattr function through safe_builtins without the required _getattr_ guard and relies on validate_code checks that only block literal dangerous dunder strings. An attacker can construct arbitrary dunder names at runtime, navigate the Python class hierarchy, and eventually access subprocess.Popen, allowing the execution of operating‑system commands with the same privileges as the server process. The execute_code MCP tool is delivered over HTTP/SSE, and when the transport is exposed without authentication, an attacker can trigger this flaw from any network location that can reach the end‑point. The vulnerability results in full remote code execution on the host running the python_sandbox_server and has a CVSS score of 10, an EPSS score of < 1%, and is not yet listed in CISA’s KEV catalog.

Affected Systems

The vulnerability impacts IBM MCP Context Forge—specifically the python_sandbox_server subproject in the MCP‑Servers bundle. All releases earlier than 1.0.2 are affected, regardless of deployment mode. The core Context Forge gateway and proxy components are not directly impacted, but the sandbox component serves as a potential foothold within the overall platform.

Risk and Exploitability

With a CVSS score of 10, the issue is classified as Critical. Although the EPSS score is low (< 1%), the fact that the execute_code tool can be accessed via unauthenticated HTTP/SSE or via local stdio‑only deployments means that remote or local attackers can exploit the flaw provided they have network reach to the server. The vulnerability is not currently listed in CISA’s KEV catalog, yet operators should prioritize remediation due to the severity and the lack of built‑in authentication for the exposed service.

Generated by OpenCVE AI on September 20, 2026 at 15:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade IBM MCP Context Forge to version 1.0.2 or later, which removes the unsafe getattr exposure.
  • Configure the python_sandbox_server deployment so that the HTTP/SSE transport for the execute_code tool is protected behind authentication or is not exposed externally.
  • Limit network access to the server process by firewalling or container isolation to reduce the attack surface.
  • If an upgrade cannot be performed immediately, disable the execute_code functionality or remove subprocess access from safe_builtins to eliminate the ability to spawn external commands.

Generated by OpenCVE AI on September 20, 2026 at 15:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xm98-3vcf-fph7 mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a required _getattr_ guard, and relies on validate_code checks for literal dangerous dunder strings. An attacker can construct dunder names at runtime, traverse the Python class hierarchy, reach subprocess.Popen, and execute OS commands with the server process privileges through the execute_code MCP tool. The HTTP/SSE transport can expose this tool without authentication, while stdio-only deployments have reduced network reachability. The issue affects the python_sandbox_server subproject and does not directly affect the core Context Forge gateway or proxy components. This issue is fixed in version 1.0.2.
Title MCP Context Forge: RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
Weaknesses CWE-693
CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:45:23.818Z

Reserved: 2026-06-10T16:43:31.241Z

Link: CVE-2026-53710

cve-icon Vulnrichment

Updated: 2026-09-15T19:16:39.303Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T17:17:19.117

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-53710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:45:17Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')