When converting MCP tools/call request to OpenAPI request, input path, query, and header values are not sanitized.
When using the MCP to OpenAPI feature, the proxy lacks proper sanitization of input parameters in the MCP call, allowing:
This vulnerability is fixed in Agentgateway v0.12.0+. Users on older versions are recommended to upgrade to v0.12.0+.
This feature only impacts usage of the MCP to OpenAPI feature
Agentgateway extends its thanks to @spacewander for the report!
{
"cwe_ids": [
"CWE-20"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-05T01:02:47Z",
"nvd_published_at": "2026-03-06T21:16:15Z",
"severity": "MODERATE"
}