THREAT OPS › Threat News › [GHSA] GHSA-vwf3-4xxj-qg6h (high) — mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
[GHSA] GHSA-vwf3-4xxj-qg6h (high) — mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
GHSA-vwf3-4xxj-qg6h Severity: high CVE: None
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
### Summary
`mcpgateway.services.prompt_service.PromptService` renders user-supplied prompt templates using Jinja2's plain `Environment()` rather than `SandboxedEnvironment`. An aut
MITRE ATT&CK techniques
Original source: https://github.com/advisories/GHSA-vwf3-4xxj-qg6h