Pypi · Mcp-Toolbox-Sdk-Python · CVE-2026-19202
**Name of the Vulnerable Software and Affected Versions**
mcp-toolbox-sdk-python (affected versions not specified)
**Description**
A caching flaw in the `toolbox-core` package allows a Google ID token to be cached and reused across different audiences within the same process. The module-level token cache fails to key cached tokens by the requested audience, which can lead to a token minted for a sensitive service being retrieved and sent to a secondary service. An attacker who controls or monitors traffic to the secondary service can capture this token and replay it to impersonate the victim application against the sensitive service.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.