CVE-2026-18486
nicheImproperly Validated jq Filters Leak Credentials in IBM ContextForge MCP Gateway
IBM ContextForge MCP Gateway (MCP Context Forge) versions through v1.0.7 do not properly validate user-supplied jq filter expressions used to shape and transform JSON payloads passing through the gateway. A remote attacker who holds any low-privileged authenticated account can submit a crafted jq filter via the gateway's API, and the improperly validated filter is then processed in a way that reaches sensitive gateway data. This lets the attacker extract credentials and secrets held by or accessible to the gateway and use them to escalate privileges to higher-level access. Any deployment running ContextForge MCP Gateway v1.0.7 or earlier is affected, especially deployments with untrusted or broadly shared user accounts. No public proof-of-concept or in-the-wild exploitation is known; EPSS estimates a roughly 0.3% probability of exploitation within 30 days and the flaw is not in CISA's KEV catalog.
What to do: Upgrade to the latest ContextForge MCP Gateway release (any version above v1.0.7) as soon as practical. Until then, limit gateway accounts to trusted users, restrict who can supply or configure jq filters, and keep the gateway off publicly reachable networks. If compromise is suspected, rotate the credentials, API keys, and secrets stored in or accessible through the gateway.
| IBM ContextForge MCP Gateway (MCP Context Forge) | <= v1.0.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.
- Vendors
- ibm
- Products
- contextforge
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.