mcp-contextforge-gateway vulnerabilities
CVEs whose affected-version data names the mcp-contextforge-gateway package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-53708Medium· 6.6PoCContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs
ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls valid…
▾ TwilightIBM · mcp-context-forgeEPSS 0.28%via NVD
GHSA-vwf3-4xxj-qg6hHighmcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
▾ Twilightmcp-contextforge-gateway · mcp-contextforge-gatewayvia GHSA