A production-grade MCP Gateway & Proxy built with FastAPI. Supports multi-server registration, virtual server composition, authentication, retry logic, observability, protocol translation, and a unified federated tool catalog.
MCP Contextforge Gateway is an MCP server that a production-grade MCP Gateway & Proxy built with FastAPI. Supports multi-server registration, virtual server composition, authentication, retry logic, observability, protocol translation, and a unified federated tool catalog. Its tool list has not been published yet over stdio and http, requires no API key, and scores 31/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients - only the file and path differ.
{
"mcpServers": {
"mcp-contextforge-gateway": {
"command": "uvx",
"args": [
"mcp-contextforge-gateway"
]
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
A production-grade MCP Gateway & Proxy built with FastAPI. Supports multi-server registration, virtual server composition, authentication, retry logic, observability, protocol translation, and a unified federated tool catalog.
Run this in your terminal to verify the server starts. Then let us know if it worked - your result helps other developers.
uvx 'mcp-contextforge-gateway' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories - click any category to see the underlying evidence.
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
**Commit:** `f855e54d5b7bc1c91b977574a03b91eff6b86bb6` **Component:** `mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py` ## Vulnerability RestrictedPython's sandbox in ContextForge's `python_sandbox_server` sub-project allows arbitrary Python execution via three compounding weaknesses: 1. Raw `getattr` is exposed in `safe_builtins`, bypassing `_getattr_` mediation. 2. `validate_code` checks for literal dangerous dunder strings, but the payload constructs th
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
### Summary `mcpgateway.services.prompt_service.PromptService` renders user-supplied prompt templates using Jinja2's plain `Environment()` rather than `SandboxedEnvironment`. An authenticated user with permission to register or update prompt templates can store a malicious template that, on subsequent rendering, executes arbitrary Python code on the gateway host with the privileges of the gateway process. This is a Server-Side Template Injection (SSTI) vulnerability leading to Remote Code Execu
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
## Summary The `/admin/gateways/test` endpoint validates submitted URLs by resolving the hostname at validation time and blocking private address ranges. The HTTP client independently re-resolves DNS at connection time with no IP binding between the two operations, creating a TOCTOU window exploitable via DNS rebinding. The source code explicitly acknowledges this limitation in two separate locations. ## Details `validate_gateway_test_url()` in `mcpgateway/common/validators.py` (lines 1527–17
This server is missing a description. Tools and install config are also missing. If you've used it, help the community.
Add informationBe the first to review
Have you used this server?
Share your experience - it helps other developers decide.
Sign in to write a review.
Others in developer-tools / devops
XcodeBuildMCP provides tools for Xcode project management, simulator management, and app utilities.
XcodeBuildMCP provides tools for Xcode project management, simulator management, and app utilities.
MCP server for using the GitLab API
Manage Supabase projects — databases, auth, storage, and edge functions
MCP Security Weekly
Get CVE alerts and security updates for Mcp Contextforge Gateway and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.