CVE-2026-77825
📛 CVE Title
IBM ContextForge MCP Gateway is affected by path traversal
Description
IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- ibm
- CVSS severity
- MEDIUM
- CVSS score
- 4.9 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N- Effective score
- 4.9 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-22 - Reserved
- 2026-08-21
- Published
- 2026-09-24 14:21 UTC
- Last updated
- 2026-09-24 14:21 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/77xxx/CVE-2026-77825.json
NVD / KEV / EPSS data refreshed 2026-09-25 04:36 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-86011 - Assigner
- ibm
- Published
- Sep 24, 2026, 2:21:18 PM
- Updated
- Sep 24, 2026, 2:21:18 PM
- EUVD base score (CVSS 3.1)
-
4.9 / 10
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N - EUVD-reported EPSS
- 0.0000
- Vendors
- IBM
- Products
-
ContextForge MCP Gateway (1.0.0 ≤1.0.8)
- Aliases
-
GHSA-6xjp-r2qh-2fj7
ENISA description: IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| IBM | ContextForge MCP Gateway |
1.0.0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- https://www.ibm.com/support/pages/node/7289314 vendor-advisorypatch
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Remediations (10)
-
web:anonhaven.com
CVE Details CVE ID CVE-2026-77825 Published Date Sep 24, 2026 Vendor IBM Severity MEDIUM CVSS v3.1 Score 4.9
2026-09-25 10:46 UTC -
web:blog.qualys.com
Key Takeaways RedSun is a critical zero-day vulnerability in Microsoft Defender that allows low-privileged users to gain SYSTEM access No patch is currently available, leaving all Defender-enabled Windows systems potentially exposed Qualys VMDR detects affected assets instantly (QID 92382) TruRisk™ Eliminate enables immediate mitigation , removing exploitability without waiting for a fix ...
2026-09-25 10:46 UTC -
web:cvetodo.com
CVE-2026-77825 is a Path Traversal vulnerability in ContextForge MCP Gateway. Full technical analysis, mitigations , and exploit status — updated in real time.
2026-09-25 10:46 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-09-25 10:46 UTC -
web:pureinfotech.com
Finally, Windows 10 1607 receives update KB5123099, which bumps the build to 14393.9512, addresses similar issues as those for version 1809, and includes a fix for the Microsoft Compatibility Telemetry service. Windows 10 September 2026 Patch Tuesday - Manual installation process
2026-09-25 10:46 UTC -
web:tech-insider.org
BlueHammer ( CVE - 2026 -33825) lets attackers hit SYSTEM on Windows via Microsoft Defender. Patched in April, now confirmed in ransomware attacks by CISA.
2026-09-25 10:46 UTC -
web:www.oracle.com
This Critical Patch Update contains 1448 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.
2026-09-25 10:46 UTC -
web:www.oracle.com
Additional CVEs addressed are: The patch for CVE - 2026 -34481 also addresses CVE - 2026 -34477, CVE - 2026 -34478, CVE - 2026 -34479, and CVE - 2026 -34480. Oracle Fusion Middleware Risk Matrix This Critical Security Patch Update contains 106 new security patches for Oracle Fusion Middleware. 53 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a ...
2026-09-25 10:46 UTC -
web:www.picussecurity.com
The exploit, referred to as "BlueHammer", was released prior to the availability of an official fix , making it a true zero-day at the time of disclosure. In this blog, we explain how the Windows Defender CVE - 2026 -33825 vulnerability works, its real-world risk to organizations, and provide practical steps for validation and remediation .
2026-09-25 10:46 UTC -
web:www.rapid7.com
CVE-2026-77825 : IBM ContextForge MCP Gateway: IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download…. View severity, references, and remediation details from Rapid7.
2026-09-25 10:46 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-77825.json.
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:ibm:contextforge_mcp_gateway:1.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:contextforge_mcp_gateway:1.0.8:*:*:*:*:*:*:*"
],
"product": "ContextForge MCP Gateway",
"vendor": "IBM",
"versions": [
{
"lessThanOrEqual": "1.0.8",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.</p>"
}
],
"value": "IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:21:18.507Z",
"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"shortName": "ibm"
},
"references": [
{
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://www.ibm.com/support/pages/node/7289314"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p><strong>IBM strongly recommends addressing the vulnerability now.</strong></p><div><table><tbody><tr><td><strong>Product(s)</strong></td><td><strong>Version(s) number and/or range\u00a0</strong></td><td><strong>Remediation/Fix/Instructions</strong></td></tr><tr><td>IBM ContextForge MCP Gateway</td><td>v1.0.0 - v1.0.8</td><td><div><div>Upgrade to version 1.0.9 or later. See <a href=\"https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.9\" rel=\"nofollow\">release notes</a></div></div></td></tr></tbody></table></div><p></p><p></p>"
}
],
"value": "IBM strongly recommends addressing the vulnerability now.\n\nProduct(s)Version(s) number and/or range\u00a0Remediation/Fix/InstructionsIBM ContextForge MCP Gatewayv1.0.0 - v1.0.8Upgrade to version 1.0.9 or later. See release notes https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.9"
}
],
"title": "IBM ContextForge MCP Gateway is affected by path traversal",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<div><div>None. IBM strongly recommends upgrading to the fixed version.</div><br/><div>As temporary mitigations until the update can be applied:</div><div>1. Disable the Admin API (`MCPGATEWAY_ADMIN_API_ENABLED=false`) if administrative endpoints are not required.</div></div>"
}
],
"value": "None. IBM strongly recommends upgrading to the fixed version.\n\n\nAs temporary mitigations until the update can be applied:\n\n1. Disable the Admin API (`MCPGATEWAY_ADMIN_API_ENABLED=false`) if administrative endpoints are not required."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"assignerShortName": "ibm",
"cveId": "CVE-2026-77825",
"datePublished": "2026-09-24T14:21:18.507Z",
"dateReserved": "2026-08-21T14:42:05.183Z",
"dateUpdated": "2026-09-24T14:21:18.507Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}