mcp-contextforge-gateway is vulnerable to Improper Authorization
49
Medium Risk
The roots service accepts arbitrary URI schemes, including file://, without validating the scheme or path, and registers them without authorization checks. Registered roots are returned to every authenticated administrator with no per-team filtering. A scoped user can register local-file URIs that other administrators and MCP clients later dereference, exposing sensitive system paths. The fix validates accepted schemes and applies ownership and per-team authorization to root registration and listing.
You are affected if you are using a version that falls within the vulnerable range and you expose the roots registration feature to multiple administrators.
mcp-contextforge-gateway is vulnerable to Improper Authorization in versions 0.0.1 - 1.0.6.
Upgrade the mcp-contextforge-gateway library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.