Metrics
Affected Vendors & Products
No advisories yet.
Solution
| Product | Affected Version(s) | Fix Version | Instructions | |---|---|---|---| | | <=1.0.4 | 1.0.5 | Upgrade to v1.0.5 or later. . | IBM strongly recommends addressing the vulnerability now. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gateway<=1.0.4 v1.0.5 or later See [release notes]( https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.5) https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.5%29 Note: <Component A / B names> are bundled with <Product profile name> to provide <feature / function description>
Workaround
There is no workaround that fully prevents the bypass while keeping the affected plugins active. Operators may disable `regex_filter` and `deny_filter` in `plugins/config.yaml` to prevent exploitation, at the cost of losing the filtering controls those plugins provide. IBM strongly recommends upgrading to v1.0.5 or higher, which replaces the top-level-only scan loops with a recursive walker in both plugins.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7285720 |
|
Tue, 15 Sep 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm contextforge-mcp-gateway
|
|
| Vendors & Products |
Ibm contextforge-mcp-gateway
|
Tue, 15 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content. | |
| Title | IBM ContextForge MCP Gateway is affected by security filter bypass via nested payload structures | |
| First Time appeared |
Ibm
Ibm contextforge Mcp Gateway |
|
| Weaknesses | CWE-184 | |
| CPEs | cpe:2.3:a:ibm:contextforge_mcp_gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm contextforge Mcp Gateway |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-15T17:28:57.954Z
Reserved: 2026-06-10T17:00:06.831Z
Link: CVE-2026-11918
No data.
Status : Received
Published: 2026-09-15T18:17:12.677
Modified: 2026-09-15T18:17:12.677
Link: CVE-2026-11918
No data.
OpenCVE Enrichment
Updated: 2026-09-15T18:30:14Z