PYPI · AUGUST 2026 · EARLY WARNING

mcp-contextforge-gateway Package Sandbox Bypass Vulnerability Alert

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
mcp-contextforge-gateway (pypi)
Affected versions
< 1.0.3 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.2.0, <= 0.2.0 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.7.0, <= 0.7.0 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 1.0.0, <= 1.0.0 or >= 1.0.0b1, <= 1.0.0b1 or >= 1.0.0b2, <= 1.0.0b2 or >= 1.0.0rc1, <= 1.0.0rc1 or >= 1.0.1, <= 1.0.1 or >= 1.0.2, <= 1.0.2 or < 1.0.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.2.0, <= 0.2.0 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.7.0, <= 0.7.0 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 1.0.0b1, <= 1.0.0b1 or >= 1.0.0b2, <= 1.0.0b2 or >= 1.0.0rc1, <= 1.0.0rc1 or < 1.0.2 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.2.0, <= 0.2.0 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.7.0, <= 0.7.0 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 1.0.0, <= 1.0.0 or >= 1.0.0b1, <= 1.0.0b1 or >= 1.0.0b2, <= 1.0.0b2 or >= 1.0.0rc1, <= 1.0.0rc1 or >= 1.0.1, <= 1.0.1 or < 1.0.3 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.2.0, <= 0.2.0 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.7.0, <= 0.7.0 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 1.0.0, <= 1.0.0 or >= 1.0.0b1, <= 1.0.0b1 or >= 1.0.0b2, <= 1.0.0b2 or >= 1.0.0rc1, <= 1.0.0rc1 or >= 1.0.1, <= 1.0.1 or >= 1.0.2, <= 1.0.2
Patched version
Not yet available
GHSA-XM98-3VCF-FPH7

An early warning has been issued for a sandbox bypass vulnerability in the mcp-contextforge-gateway package that could allow arbitrary Python execution.

What happened

An early warning has been issued regarding a sandbox bypass vulnerability in the mcp-contextforge-gateway package. This vulnerability, tracked as GHSA-XM98-3VCF-FPH7, allows arbitrary Python execution which can lead to OS command execution with server process privileges. The vulnerability was first flagged on August 24, 2026. The affected versions include all versions less than 1.0.3 and various other specified ranges as detailed in the threat data.

The vulnerability appears to exploit a bypass in the RestrictedPython sandbox via the getattr builtin in python_sandbox_server. This can potentially allow an attacker to execute arbitrary Python code, leading to further compromise of the server process.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If mcp-contextforge-gateway is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are potentially affected if you are using the mcp-contextforge-gateway package in versions less than 1.0.3 or within the specified vulnerable version ranges.

What should I do right now?

Monitor for patches and upgrade to a fixed version once available. Review your application's use of the package and consider additional security measures.

Is there an official fix available?

No official fix has been published yet. Monitor the sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats