IBM ContextForge MCP Gateway 1.0.0 至 1.0.8 版本在其 Admin API 的日志下载端点( )中存在路径遍历漏洞。该漏洞的路径隔离检查使用了 方法,而非正确的边界验证,导致已认证的管理员可以通过构造一个能解析为与日志目录具有相同字符串前缀的父级或同级目录的文件名,从而读取配置 之外的 、 和 文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | ContextForge MCP Gateway | 1.0.0 ~ 1.0.8 |
cpe:2.3:a:ibm:contextforge_mcp_gateway:1.0.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81549 | 9.6 CRITICAL | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-82093 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81552 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81548 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81547 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81545 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81539 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-77874 | 8.6 HIGH | IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities |
| CVE-2026-82094 | 7.1 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-6544 | 6.2 MEDIUM | Multiple Vulnerabilities in IBM Concert Software |
| CVE-2026-17504 | 5.1 MEDIUM | This Power System update is being released to address |
| CVE-2026-17503 | 5.1 MEDIUM | This Power System update is being released to address |
| CVE-2026-17413 | 5.1 MEDIUM | This Power System update is being released to address |
| CVE-2026-18870 | 4.3 MEDIUM | This Power System update is being released to address |
| CVE-2026-18857 | 3.4 LOW | This Power System update is being released to address |
| CVE-2026-17511 | 3.4 LOW | This Power System update is being released to address |
| CVE-2026-18104 | 3.3 LOW | IBM Db2 Mirror for i is vulnerable to obtain sensitive information [] |
| CVE-2026-19492 | 3.2 LOW | This Power System update is being released to address |
No comments yet