{"api_version":"v1","generated_at":"2026-10-09T08:35:00+00:00","product":{"cve_count":1,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-ibm-contextforge-mcp-gateway-translate-utility-8a4357a9851a","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"ContextForge MCP Gateway - Translate utility","next_cursor":null,"observations":[{"affected":"ContextForge MCP Gateway - Translate utility: <= 1.0.8","affected_versions_present":true,"cve_id":"CVE-2026-18489","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-18489","fixed":"IBM strongly recommends addressing the vulnerability now.; The IBM ContextForge Translate service is intended **only for local, single-session development use**. It does not provide the session isolation required for production or multi-client deployments. Users must ensure the Translate service is not exposed in any production capacity.; PR [#6388]( https://github.com/IBM/mcp-context-forge/pull/6388) https://github.com/IBM/mcp-context-forge/pull/6388%29 (merged 2026-08-24) updates the product documentation to make this restriction explicit, removing previous guidance that could have implied multi-tenant production suitability.","last_modified":"2026-09-04T17:29:57.267Z","patch_url":"https://www.ibm.com/support/pages/node/7286056","primary_source":"","published":"2026-09-04T16:23:08.905Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"IBM"}}
