Intel

AIKIDO-2026-683466

mcp-contextforge-gateway is vulnerable to Authentication Bypass

Authentication BypassGHSA-8pcq-mx48-hjvj Published 6 days ago

98

Critical Risk

This Affects:

PYTHONmcp-contextforge-gateway
0.0.1 - 1.0.6
Fixed in 1.0.7
Are you affected? Scan for Free

TL;DR

The gateway ships a publicly known default HMAC secret for signing JWTs in its Docker Compose configuration. When deployed with the documented quickstart and default settings, the signing secret is never overridden and database user requirements are disabled. A remote unauthenticated party can create a JWT that asserts platform-administrator identity and obtain full control of the gateway. The fix removes the shared default secret and requires an explicit strong signing key before startup.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you deploy the gateway using the default Docker Compose configuration without overriding the JWT signing secret.

Background info

mcp-contextforge-gateway is vulnerable to Authentication Bypass in versions 0.0.1 - 1.0.6.

How to fix this

Upgrade the mcp-contextforge-gateway library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform