cbcvebase.

Google Mcp Toolbox For Databases vulnerabilities

8 known vulnerabilities affecting google/mcp_toolbox_for_databases.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH3

Vulnerabilities

Page 1 of 1
CVE-2026-11717P2CRITICALCVSS 9.3≥ 1.0.0, ≤ 1.3.02026-06-18
CVE-2026-11717 [CRITICAL] CWE-287 CVE-2026-11717: An authentication bypass vulnerability exists in the generic opaque token validation path (validateO An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When verifying an unparsed opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), the toolbox decodes the response into an introspectResp struct where the Active field is declared as a pointer to a b
nvd
CVE-2026-15829P3HIGHCVSS 8.6≥ 0.13.0, ≤ 1.3.02026-07-21
CVE-2026-15829 [HIGH] CWE-89 CVE-2026-15829: A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and interpolates them unescaped via fmt.Sprintf directly into a generated AI.
nvd
CVE-2026-11718P3CRITICALCVSS 9.3≥ 1.0.0, ≤ 1.3.02026-06-18
CVE-2026-11718 [CRITICAL] CWE-287 CVE-2026-11718: An authentication bypass vulnerability exists in the generic opaque token validation path (validateO An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the toolbox validates an opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), it decodes the response into an introspectResp struct. However, the subsequent claim-checking logic (validateClaim
nvd
CVE-2026-11720P3CRITICALCVSS 9.1fixed in 1.3.02026-06-29
CVE-2026-11720 [CRITICAL] CWE-22 CVE-2026-11720: A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While it checks that the input does not alter the scheme, host, or user info,
nvd
CVE-2026-11719P3HIGHCVSS 8.6v1.3.02026-06-18
CVE-2026-11719 [HIGH] CWE-862 CVE-2026-11719: An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missi An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers. While the 2025-11-25 protocol version handler correctly enforces per-tool restrictions defined by scopesRequired, older supported protocol versions (2025-06-18, 2025-03-26, and 2024-11-05) omit this
nvd
CVE-2026-9739P3CRITICALCVSS 9.4fixed in PR 3054 (Fix CORS bypass)2026-05-27
CVE-2026-9739 [CRITICAL] CWE-942 CVE-2026-9739: Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we i Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. However, the hardcoded `Access-Control-Allow-Origin: *` header in the SSE initialization handler was inadvertently retained. This vulnerability specifically
nvd
CVE-2026-16481P3HIGHCVSS 8.4≥ 0.19.1, ≤ 1.4.02026-07-27
CVE-2026-16481 [HIGH] CWE-918 CVE-2026-16481: A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-h A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an authenticated client. The underlying transport automatically attaches an Authorizati
nvd
CVE-2026-11624P3CRITICALCVSS 9.4fixed in 0.25.02026-06-13
CVE-2026-11624 [CRITICAL] CWE-346 CVE-2026-11624: The Model Context Protocol has a security warning advising servers to validate the "Origin" header o The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. In v0.25.0, a new "--allowed-hosts" flag was introduced alongside the existing "--allowed-origins" flag, enabl
nvd
Google Mcp Toolbox For Databases vulnerabilities | cvebase