Vulnerability  ·  2026-09-25

IBM ContextForge MCP Gateway: admin API log-download path traversal reads files outside LOG_FOLDER (CVE-2026-77825, CVSS 4.9)

VulnerabilityMedium impactGlobalCVE-2026-77825
IBM ContextForge MCP Gateway 1.0.0-1.0.8 admin API endpoint GET /v1/admin/logs/file uses str.startswith() for path confinement, allowing an authenticated admin to read .log/.jsonl/.json files outside LOG_FOLDER by choosing a sibling-directory filename sharing the log directory string prefix.
An MCP gateway admin account reading arbitrary JSON/log files on the host could expose agent runtime secrets, LLM API keys, or captured tool traffic outside the intended log sandbox in production agent gateways.
Authenticated admin crafts a log filename resolving into a sibling directory sharing the log path prefix to read arbitrary .log/.jsonl/.json files.
IBM ContextForge MCP Gateway 1.0.0-1.0.8
Apply IBM update per node/7289314; restrict admin access to the gateway.
NVD CVE-2026-77825IBM security page 7289314
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →