CyberRota Analysis
AI-GeneratedIBM ContextForge MCP Gateway versions 1.0.0 to 1.0.8 are vulnerable to a path traversal attack via the Admin API log-download endpoint, allowing authenticated administrators to access sensitive log files outside the designated log directory. This vulnerability could lead to unauthorized exposure of potentially sensitive information, impacting the confidentiality of the system. Organizations using this software should prioritize remediation to mitigate the risk of data leakage.
Original NVD Description
IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.
Related CVEs
Other vulnerabilities affecting the same vendor(s)