Skip to content

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

High severity GitHub Reviewed Published Jun 15, 2026 in IBM/mcp-context-forge • Updated Aug 25, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts