mcp-contextforge-gateway is vulnerable to SQL Injection
88
High Risk
Two security plugins validate input with regular expressions and string matching whose view of the data diverges from the executor grammar. The SQL sanitizer can be bypassed with crafted string literals and comments to run privilege changes, table drops, and mass deletions. The resource filter can be bypassed through URL userinfo parsing differences to reach internal network destinations. The fix replaces the string checks with parser-based validation so the plugin and executor agree on the input.
You are affected if you are using a version that falls within the vulnerable range and you rely on the SQL sanitizer or resource filter plugins to enforce security policy.
mcp-contextforge-gateway is vulnerable to SQL Injection in versions 0.0.1 - 1.0.6.
Upgrade the mcp-contextforge-gateway library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.