Intel

AIKIDO-2026-803826

mcp-contextforge-gateway is vulnerable to Improper Authorization

Improper AuthorizationGHSA-x39c-q2jx-f325 Published 6 days ago

49

Medium Risk

This Affects:

PYTHONmcp-contextforge-gateway
0.0.1 - 1.0.6
Fixed in 1.0.7
Are you affected? Scan for Free

TL;DR

The roots service accepts arbitrary URI schemes, including file://, without validating the scheme or path, and registers them without authorization checks. Registered roots are returned to every authenticated administrator with no per-team filtering. A scoped user can register local-file URIs that other administrators and MCP clients later dereference, exposing sensitive system paths. The fix validates accepted schemes and applies ownership and per-team authorization to root registration and listing.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you expose the roots registration feature to multiple administrators.

Background info

mcp-contextforge-gateway is vulnerable to Improper Authorization in versions 0.0.1 - 1.0.6.

How to fix this

Upgrade the mcp-contextforge-gateway library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform