mcp-contextforge-gateway Package Sandbox Bypass Vulnerability Alert
- Severity
- HIGH
- Affected component
- mcp-contextforge-gateway (pypi)
- Affected versions
- < 1.0.3 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.2.0, <= 0.2.0 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.7.0, <= 0.7.0 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 1.0.0, <= 1.0.0 or >= 1.0.0b1, <= 1.0.0b1 or >= 1.0.0b2, <= 1.0.0b2 or >= 1.0.0rc1, <= 1.0.0rc1 or >= 1.0.1, <= 1.0.1 or >= 1.0.2, <= 1.0.2 or < 1.0.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.2.0, <= 0.2.0 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.7.0, <= 0.7.0 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 1.0.0b1, <= 1.0.0b1 or >= 1.0.0b2, <= 1.0.0b2 or >= 1.0.0rc1, <= 1.0.0rc1 or < 1.0.2 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.2.0, <= 0.2.0 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.7.0, <= 0.7.0 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 1.0.0, <= 1.0.0 or >= 1.0.0b1, <= 1.0.0b1 or >= 1.0.0b2, <= 1.0.0b2 or >= 1.0.0rc1, <= 1.0.0rc1 or >= 1.0.1, <= 1.0.1 or < 1.0.3 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.2.0, <= 0.2.0 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.7.0, <= 0.7.0 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 1.0.0, <= 1.0.0 or >= 1.0.0b1, <= 1.0.0b1 or >= 1.0.0b2, <= 1.0.0b2 or >= 1.0.0rc1, <= 1.0.0rc1 or >= 1.0.1, <= 1.0.1 or >= 1.0.2, <= 1.0.2
- Patched version
- Not yet available
An early warning has been issued for a sandbox bypass vulnerability in the mcp-contextforge-gateway package that could allow arbitrary Python execution.
What happened
An early warning has been issued regarding a sandbox bypass vulnerability in the mcp-contextforge-gateway package. This vulnerability, tracked as GHSA-XM98-3VCF-FPH7, allows arbitrary Python execution which can lead to OS command execution with server process privileges. The vulnerability was first flagged on August 24, 2026. The affected versions include all versions less than 1.0.3 and various other specified ranges as detailed in the threat data.
The vulnerability appears to exploit a bypass in the RestrictedPython sandbox via the getattr builtin in python_sandbox_server. This can potentially allow an attacker to execute arbitrary Python code, leading to further compromise of the server process.
What to do about it
- Monitor the primary sources for any updates or patches released for the mcp-contextforge-gateway package.
- If a patch is released, upgrade to the fixed version immediately to mitigate the risk.
- Review your application's use of the mcp-contextforge-gateway package and assess the potential impact of this vulnerability.
- Consider implementing additional security measures to restrict the execution of arbitrary Python code in your environment.
- Stay informed about the latest security advisories and updates related to the mcp-contextforge-gateway package.
How 0Day would have caught this
mcp-contextforge-gateway is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are potentially affected if you are using the mcp-contextforge-gateway package in versions less than 1.0.3 or within the specified vulnerable version ranges.
What should I do right now?
Monitor for patches and upgrade to a fixed version once available. Review your application's use of the package and consider additional security measures.
Is there an official fix available?
No official fix has been published yet. Monitor the sources for updates.