GHSA-v2x6-wwfw-r2rq

Suggest an improvement
Source
https://github.com/advisories/GHSA-v2x6-wwfw-r2rq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-v2x6-wwfw-r2rq/GHSA-v2x6-wwfw-r2rq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v2x6-wwfw-r2rq
Aliases
Published
2026-03-05T01:02:47Z
Modified
2026-03-06T23:01:26Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Agentgateway is missing parameter sanitization in MCP to OpenAPI conversion
Details

Summary

When converting MCP tools/call request to OpenAPI request, input path, query, and header values are not sanitized.

Details

When using the MCP to OpenAPI feature, the proxy lacks proper sanitization of input parameters in the MCP call, allowing:

  • Injection of additional path or query parameters.
  • Injection of additional headers.

Impacted Versions

This vulnerability is fixed in Agentgateway v0.12.0+. Users on older versions are recommended to upgrade to v0.12.0+.

This feature only impacts usage of the MCP to OpenAPI feature

Credits

Agentgateway extends its thanks to @spacewander for the report!

Database specific
{
    "cwe_ids":  [
        "CWE-20"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-05T01:02:47Z",
    "nvd_published_at":  "2026-03-06T21:16:15Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/agentgateway/agentgateway

Package

Name
github.com/agentgateway/agentgateway
View open source insights on deps.dev
Purl
pkg:golang/github.com/agentgateway/agentgateway

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.12.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-v2x6-wwfw-r2rq/GHSA-v2x6-wwfw-r2rq.json"