Google Mcp-Toolbox vulnerabilities
5 known vulnerabilities affecting google/mcp-toolbox.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-14537P2CRITICALCVSS 9.8v1.3.0vv1.4.02026-07-31
CVE-2026-14537 [CRITICAL] CWE-863 CVE-2026-14537: Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versio
Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.
nvd
CVE-2026-14538P3HIGHCVSS 7.7≥ 0.16.1, ≤ 1.4.02026-07-31
CVE-2026-14538 [HIGH] CWE-285 CVE-2026-14538: An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql too
An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset restrictions, but due to a fail-open logic fl
nvd
CVE-2026-14541P3HIGHCVSS 7.5v1.4.02026-07-31
CVE-2026-14541 [HIGH] CWE-287 CVE-2026-14541: An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider co
An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation entirely. As a res
nvd
CVE-2026-14539P3HIGHCVSS 7.5≥ 0.0.0, ≤ 1.4.02026-07-31
CVE-2026-14539 [HIGH] CWE-770 CVE-2026-14539: An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-
An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted buffer loop (io.ReadAll) without applyi
nvd
CVE-2026-14540P4MEDIUMCVSS 6.1≥ 0.3.0, ≤ 1.4.02026-07-31
CVE-2026-14540 [MEDIUM] CWE-918 CVE-2026-14540: A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool compon
A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to safely regulate request redirection b
nvd