GHSA-vwf3-4xxj-qg6h
### Summary `mcpgateway.services.prompt_service.PromptService` renders user-supplied prompt templates using Jinja2's plain `Environment()` rather than `SandboxedEnvironment`. An authenticated user with permission to register or update prompt templates can store a malicious template that, on subsequent rendering, executes arbitrary Python code on the gateway host with the privileges of the gateway process. This is a Server-Side Template Injection (SSTI) vulnerability leading to Remote Code Execution. ### Details **Affected component:** `mcpgateway/services/prompt_service.py` **Affected version:** `0.9.0` (verified). The fix in the unreleased `main` branch indicates all earlier published versions are likewise affected. **Vulnerable code** `mcpgateway/services/prompt_service.py`, line 26: ```python from jinja2 import Environment, meta, select_autoescape ``` `mcpgateway/services/prompt_service.py`, line 135 (inside `PromptService.__init__`): ```python self._jinja_env = Environment( autoescape=select_autoescape(["html", "xml"]), trim_blocks=True, lstrip_blocks=True, ) ``` `mcpgateway/services/prompt_service.py`, lines 1592–1616 (`_render_template`): ```python def _render_template(self, template: str, arguments: Dict[str, str]) -> str: ... try: jinja_template = self._jinja_env.from_string(template) return jinja_template.render(**arguments) except Exception: try: return template.format(**arguments) except Exception as e: raise PromptError(f"Failed to render template: {str(e)}") ``` `_render_template` is invoked from `PromptService.get_prompt` (line 892): ```python rendered = self._render_template(prompt.template, arguments) ``` Where `prompt.template` is loaded from the database. The `template` field of the database row is populated via the `register_prompt`, `update_prompt`, and `register_prompts_bulk` API endpoints, which accept attacker-controlled template content from authentic
Properties
- ghsa_id
- GHSA-vwf3-4xxj-qg6h
- summary
- mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
- severity
- high
- cve_id
- GHSA-vwf3-4xxj-qg6h
- is_ghsa_only
- true
- ghsa_published
- 2026-08-25T17:42:11Z
- source_url
- https://github.com/advisories/GHSA-vwf3-4xxj-qg6h
- ghsa_updated
- 2026-08-25T17:42:14Z
Related Entities (5)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
Explore deeper with Ninja Signal's threat intelligence graph