agent-mcp-gateway@0.1.3 vulnerabilities

An MCP gateway that aggregates your existing MCP servers and lets you define which servers and individual tools each agent or subagent can access. Solves Claude Code's MCP context window waste where all tool definitions load upfront instead of being discovered when actually needed.

  • latest version

    0.2.5

  • latest non vulnerable version

  • first published

    3 months ago

  • latest version published

    2 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the agent-mcp-gateway package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Incorrect Authorization

    agent-mcp-gateway is an An MCP gateway that aggregates your existing MCP servers and lets you define which servers and individual tools each agent or subagent can access. Solves Claude Code's MCP context window waste where all tool definitions load upfront instead of being discovered when actually needed.

    Affected versions of this package are vulnerable to Incorrect Authorization due to improper rule evaluation in the policy engine. The authorization logic fails to prioritize deny rules over allow rules, allowing explicit allow permissions to override broader wildcard deny policies. An attacker with access to policy-controlled endpoints can exploit this behavior to gain unauthorized access to restricted resources.

    How to fix Incorrect Authorization?

    Upgrade agent-mcp-gateway to version 0.2.0 or higher.

    [,0.2.0)