CVE-2026-77825: IBM ContextForge MCP Gateway is affected by path traversal

Published Sep 24, 2026
·
Updated

IBM ContextForge Gateway was vulnerable to path traversal in its Admin API log-download endpoint (GET /v1/admin/logs/file). The path confinement check uses str.startswith() rather than proper boundary validation, allowing an authenticated admin to read .log, .jsonl, and .json files outside the configured LOGFOLDER by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.

Other sources

IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (GET /v1/admin/logs/file). The path confinement check uses str.startswith() rather than proper boundary validation, allowing an authenticated admin to read .log, .jsonl, and .json files outside the configured LOGFOLDER by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.

— MITRE

Affected Software

1 affected componentFixes available
IBM ContextForge MCP Gateway<=v1.0.0 - v1.0.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade IBM ContextForge MCP Gateway to a version that resolves this vulnerability.

    Fixed in 1.0.9

Event History

Sep 24, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

Which deployments are affected?

IBM ContextForge MCP Gateway versions 1.0.0 through 1.0.8 are affected. The issue is in the Admin API log-download endpoint at GET /v1/admin/logs/file.

2

What access does an attacker need?

An attacker must be authenticated as an administrator. No user interaction is required, and the vulnerable endpoint is reachable over the network.

3

What files could be exposed?

An authenticated administrator can read files outside the configured LOG_FOLDER when they are in a sibling directory whose absolute path shares the log directory's string prefix. The disclosed file types are .log, .jsonl, and .json.

4

How can I assess whether a system is exposed?

Check whether the gateway version is between 1.0.0 and 1.0.8 and whether the Admin API endpoint GET /v1/admin/logs/file is available. Exposure requires accessible files with the permitted extensions in a sibling directory matching the LOG_FOLDER path prefix condition.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203