mcp-contextforge-gateway is vulnerable to Improper Authorization
77
High Risk
The read endpoints for plugin-binding policies do not validate that the caller belongs to the owning team. An authenticated non-admin tenant can retrieve policies belonging to other teams, including full configuration dictionaries that typically hold plugin secrets and API keys, along with creator email addresses. Write and delete operations enforce team scoping, but the read routes do not. The fix restricts read results to the caller's authorized teams.
You are affected if you are using a version that falls within the vulnerable range and you host multiple teams or tenants that rely on team scoping of plugin-binding policies.
mcp-contextforge-gateway is vulnerable to Improper Authorization in versions 0.0.1 - 1.0.4.
Upgrade the mcp-contextforge-gateway library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.