mcp-contextforge-gateway@1.0.0

ContextForge AI Gateway — an AI gateway, registry, and proxy for MCP, A2A, and REST/gRPC APIs. Exposes a unified control plane with centralized governance, discovery, and observability. Optimizes agent and tool calling, and supports plugins.

  • latest version

    1.0.11

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    3 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the mcp-contextforge-gateway package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Server-side Request Forgery (SSRF)

    mcp-contextforge-gateway is a ContextForge AI Gateway — an AI gateway, registry, and proxy for MCP, A2A, and REST/gRPC APIs. Exposes a unified control plane with centralized governance, discovery, and observability. Optimizes agent and tool calling, and supports plugins.

    Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in the /admin/gateways/test endpoint due to a race condition between DNS resolution at validation time and at connection time, allowing DNS rebinding. An attacker can access internal network resources and potentially retrieve sensitive cloud credentials by submitting a crafted URL and manipulating DNS responses between validation and connection. This is only exploitable if the MCPGATEWAY_ADMIN_API_ENABLED configuration is set to true and the attacker possesses a credential with the gateways.read permission assigned via a database role.

    How to fix Server-side Request Forgery (SSRF)?

    Upgrade mcp-contextforge-gateway to version 1.0.3 or higher.

    [,1.0.3)
    • C
    Protection Mechanism Failure

    mcp-contextforge-gateway is a ContextForge AI Gateway — an AI gateway, registry, and proxy for MCP, A2A, and REST/gRPC APIs. Exposes a unified control plane with centralized governance, discovery, and observability. Optimizes agent and tool calling, and supports plugins.

    Affected versions of this package are vulnerable to Protection Mechanism Failure via the python_sandbox_server process. An attacker can execute arbitrary operating system commands by submitting crafted payloads that exploit exposed built-in functions and bypass code validation checks through the HTTP endpoint.

    How to fix Protection Mechanism Failure?

    Upgrade mcp-contextforge-gateway to version 1.0.2 or higher.

    [,1.0.2)