PT-2026-102751 · Google · Mcp Toolbox For Databases
CVE-2026-102242
·
Published
2026-09-29
·
Updated
2026-09-29
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0
Description
Improper link resolution in the
allowedLocalRoots path validation allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions using symbolic links. The system performs lexical directory checks without first resolving symbolic links, enabling an attacker to access or overwrite arbitrary local files located outside the permitted root directories.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcp Toolbox For Databases