Intel

AIKIDO-2026-645779

mcp-contextforge-gateway is vulnerable to Improper Authorization

Improper AuthorizationGHSA-55gx-p285-xw7f Published 6 days ago

77

High Risk

This Affects:

PYTHONmcp-contextforge-gateway
0.0.1 - 1.0.4
Fixed in 1.0.5
Are you affected? Scan for Free

TL;DR

The read endpoints for plugin-binding policies do not validate that the caller belongs to the owning team. An authenticated non-admin tenant can retrieve policies belonging to other teams, including full configuration dictionaries that typically hold plugin secrets and API keys, along with creator email addresses. Write and delete operations enforce team scoping, but the read routes do not. The fix restricts read results to the caller's authorized teams.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you host multiple teams or tenants that rely on team scoping of plugin-binding policies.

Background info

mcp-contextforge-gateway is vulnerable to Improper Authorization in versions 0.0.1 - 1.0.4.

How to fix this

Upgrade the mcp-contextforge-gateway library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform