Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environment. Prior to version 0.12.0, when converting MCP tools/call request to OpenAPI request, input path, query, and header values are not sanitized. This issue has been patched in version 0.12.0.
References
| Link | Resource |
|---|---|
| https://github.com/agentgateway/agentgateway/security/advisories/GHSA-v2x6-wwfw-r2rq | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-03-06 21:16
Updated : 2026-03-18 19:03
NVD link : CVE-2026-29791
Mitre link : CVE-2026-29791
CVE.ORG link : CVE-2026-29791
JSON object : View
Products Affected
lfprojects
- agentgateway
CWE
