Google

Mcp Toolbox For Databases

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 29.09.2026 17:47:16
  • Zuletzt bearbeitet 29.09.2026 21:36:39

Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary r...

  • EPSS 0.23%
  • Veröffentlicht 31.07.2026 01:48:39
  • Zuletzt bearbeitet 08.08.2026 00:06:32

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience o...

Medienbericht
  • EPSS 0.12%
  • Veröffentlicht 31.07.2026 01:46:54
  • Zuletzt bearbeitet 08.08.2026 00:15:26

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the ...

  • EPSS 0.21%
  • Veröffentlicht 31.07.2026 01:45:35
  • Zuletzt bearbeitet 08.08.2026 00:20:12

An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads inco...

  • EPSS 0.19%
  • Veröffentlicht 31.07.2026 01:42:29
  • Zuletzt bearbeitet 08.08.2026 00:25:01

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The tool...

  • EPSS 0.22%
  • Veröffentlicht 31.07.2026 01:38:18
  • Zuletzt bearbeitet 08.08.2026 00:25:43

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests th...

  • EPSS 0.25%
  • Veröffentlicht 27.07.2026 19:17:14
  • Zuletzt bearbeitet 28.09.2026 13:44:19

A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET requ...

  • EPSS 0.18%
  • Veröffentlicht 21.07.2026 16:39:54
  • Zuletzt bearbeitet 22.09.2026 12:50:32

A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and...

  • EPSS 0.38%
  • Veröffentlicht 29.06.2026 17:51:30
  • Zuletzt bearbeitet 01.07.2026 19:55:36

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting st...

  • EPSS 0.15%
  • Veröffentlicht 18.06.2026 11:55:03
  • Zuletzt bearbeitet 17.08.2026 15:59:07

An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers. While the 2025-11-25 protocol version handler correctly enforces per-tool restrictions defined b...