Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3862
  • PyPI/mcp-contextforge-gateway
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server 10 Sep
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-vwf3-4xxj-qg6h
  • PyPI/mcp-contextforge-gateway
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment 25 Aug
  • Fix available
GHSA-xm98-3vcf-fph7
  • PyPI/mcp-contextforge-gateway
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server 24 Aug
  • Fix available
  • Severity - 10.0 (Critical)
PYSEC-2026-3684
  • PyPI/mcp-contextforge-gateway
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) 19 Aug
  • Fix available
  • Severity - 6.6 (Medium)
GHSA-9hgc-g3w5-67cm
  • PyPI/mcp-contextforge-gateway
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) 14 Aug
  • Fix available
  • Severity - 6.6 (Medium)