PT-2026-102751 · Google · Mcp Toolbox For Databases

CVE-2026-102242

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0
Description Improper link resolution in the allowedLocalRoots path validation allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions using symbolic links. The system performs lexical directory checks without first resolving symbolic links, enabling an attacker to access or overwrite arbitrary local files located outside the permitted root directories.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102242

Affected Products

Mcp Toolbox For Databases