s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2026-77825

📛 CVE Title

IBM ContextForge MCP Gateway is affected by path traversal

Description

IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.

Overview

State
PUBLISHED
Assigner (CNA)
ibm
CVSS severity
MEDIUM
CVSS score
CVSS 4.9 / 10 4.9 4.9 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Effective score
4.9 / 10 MEDIUM source: CNA overview
CWE(s)
CWE-22
Reserved
2026-08-21
Published
2026-09-24 14:21 UTC
Last updated
2026-09-24 14:21 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/77xxx/CVE-2026-77825.json

NVD / KEV / EPSS data refreshed 2026-09-25 04:36 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-86011
Assigner
ibm
Published
Sep 24, 2026, 2:21:18 PM
Updated
Sep 24, 2026, 2:21:18 PM
EUVD base score (CVSS 3.1)
4.9 / 10
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EUVD-reported EPSS
0.0000
Vendors
IBM
Products
ContextForge MCP Gateway (1.0.0 ≤1.0.8)
Aliases
GHSA-6xjp-r2qh-2fj7

ENISA description: IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
IBM ContextForge MCP Gateway 1.0.0 (affected) —

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Remediations (10)

  • web:anonhaven.com

    CVE Details CVE ID CVE-2026-77825 Published Date Sep 24, 2026 Vendor IBM Severity MEDIUM CVSS v3.1 Score 4.9

    2026-09-25 10:46 UTC
  • web:blog.qualys.com

    Key Takeaways RedSun is a critical zero-day vulnerability in Microsoft Defender that allows low-privileged users to gain SYSTEM access No patch is currently available, leaving all Defender-enabled Windows systems potentially exposed Qualys VMDR detects affected assets instantly (QID 92382) TruRisk™ Eliminate enables immediate mitigation , removing exploitability without waiting for a fix ...

    2026-09-25 10:46 UTC
  • web:cvetodo.com

    CVE-2026-77825 is a Path Traversal vulnerability in ContextForge MCP Gateway. Full technical analysis, mitigations , and exploit status — updated in real time.

    2026-09-25 10:46 UTC
  • web:msrc.microsoft.com

    Security Update Guide - Microsoft Security Response Center

    2026-09-25 10:46 UTC
  • web:pureinfotech.com

    Finally, Windows 10 1607 receives update KB5123099, which bumps the build to 14393.9512, addresses similar issues as those for version 1809, and includes a fix for the Microsoft Compatibility Telemetry service. Windows 10 September 2026 Patch Tuesday - Manual installation process

    2026-09-25 10:46 UTC
  • web:tech-insider.org

    BlueHammer ( CVE - 2026 -33825) lets attackers hit SYSTEM on Windows via Microsoft Defender. Patched in April, now confirmed in ransomware attacks by CISA.

    2026-09-25 10:46 UTC
  • web:www.oracle.com

    This Critical Patch Update contains 1448 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.

    2026-09-25 10:46 UTC
  • web:www.oracle.com

    Additional CVEs addressed are: The patch for CVE - 2026 -34481 also addresses CVE - 2026 -34477, CVE - 2026 -34478, CVE - 2026 -34479, and CVE - 2026 -34480. Oracle Fusion Middleware Risk Matrix This Critical Security Patch Update contains 106 new security patches for Oracle Fusion Middleware. 53 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a ...

    2026-09-25 10:46 UTC
  • web:www.picussecurity.com

    The exploit, referred to as "BlueHammer", was released prior to the availability of an official fix , making it a true zero-day at the time of disclosure. In this blog, we explain how the Windows Defender CVE - 2026 -33825 vulnerability works, its real-world risk to organizations, and provide practical steps for validation and remediation .

    2026-09-25 10:46 UTC
  • web:www.rapid7.com

    CVE-2026-77825 : IBM ContextForge MCP Gateway: IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download…. View severity, references, and remediation details from Rapid7.

    2026-09-25 10:46 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-77825.json.

{
  "containers": {
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:contextforge_mcp_gateway:1.0.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:contextforge_mcp_gateway:1.0.8:*:*:*:*:*:*:*"
          ],
          "product": "ContextForge MCP Gateway",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "1.0.8",
              "status": "affected",
              "version": "1.0.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "<p>IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.</p>"
            }
          ],
          "value": "IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-22",
              "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T14:21:18.507Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7289314"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "<p><strong>IBM strongly recommends addressing the vulnerability now.</strong></p><div><table><tbody><tr><td><strong>Product(s)</strong></td><td><strong>Version(s) number and/or range\u00a0</strong></td><td><strong>Remediation/Fix/Instructions</strong></td></tr><tr><td>IBM ContextForge MCP Gateway</td><td>v1.0.0 - v1.0.8</td><td><div><div>Upgrade to version 1.0.9 or later. See <a href=\"https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.9\" rel=\"nofollow\">release notes</a></div></div></td></tr></tbody></table></div><p></p><p></p>"
            }
          ],
          "value": "IBM strongly recommends addressing the vulnerability now.\n\nProduct(s)Version(s) number and/or range\u00a0Remediation/Fix/InstructionsIBM ContextForge MCP Gatewayv1.0.0 - v1.0.8Upgrade to version 1.0.9 or later. See  release notes https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.9"
        }
      ],
      "title": "IBM ContextForge MCP Gateway is affected by path traversal",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "<div><div>None. IBM strongly recommends upgrading to the fixed version.</div><br/><div>As temporary mitigations until the update can be applied:</div><div>1. Disable the Admin API (`MCPGATEWAY_ADMIN_API_ENABLED=false`) if administrative endpoints are not required.</div></div>"
            }
          ],
          "value": "None. IBM strongly recommends upgrading to the fixed version.\n\n\nAs temporary mitigations until the update can be applied:\n\n1. Disable the Admin API (`MCPGATEWAY_ADMIN_API_ENABLED=false`) if administrative endpoints are not required."
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-77825",
    "datePublished": "2026-09-24T14:21:18.507Z",
    "dateReserved": "2026-08-21T14:42:05.183Z",
    "dateUpdated": "2026-09-24T14:21:18.507Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}