Path Traversal Vulnerability in IBM ContextForge MCP Gateway
CVE-2026-77825
4.9MEDIUM
What is CVE-2026-77825?
IBM ContextForge MCP Gateway versions 1.0.0 to 1.0.8 are susceptible to a path traversal vulnerability within the Admin API log-download endpoint. An authentication flaw allows an authenticated administrator to access log and JSON files located outside the designated log directory by manipulating the filename. The inadequate path checking mechanism, which relies on string prefix checks, can result in unauthorized file access, potentially exposing sensitive information to administrators who should not have such access. An immediate patch is recommended to ensure proper boundary validation and secure log file handling.
Affected Version(s)
ContextForge MCP Gateway 1.0.0 <= 1.0.8