mcp-context-forge vulnerabilities
CVEs whose affected-version data names the mcp-context-forge package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-53710Critical· 10.0MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs
MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw geta…
▾ MidnightIBM · mcp-context-forgeEPSS 0.83%via NVD
CVE-2026-53708Medium· 6.6PoCContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs
ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls valid…
▾ TwilightIBM · mcp-context-forgeEPSS 0.28%via NVD