PT-2026-61987 · Google+1 · Mcp Toolbox For Databases+1
CVE-2026-15829
·
Published
2026-07-21
·
Updated
2026-07-21
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
googleapis/mcp-toolbox (affected versions not specified)
Description
A SQL injection and security boundary bypass issue exists in the prebuilt BigQuery forecasting tool (bigquery-forecast). The tool accepts client-controlled parameters
data col, timestamp col, and id cols as plain strings and interpolates them unescaped via fmt.Sprintf directly into a generated AI.FORECAST table-valued SELECT statement. Although an allowedDatasets mechanism is used to restrict queries, it only validates the history data parameter, and the final assembled query is executed without further validation. This allows an attacker to break out of string literal fields to inject multi-statement or cross-dataset query blocks, bypassing the configured boundary to read arbitrary BigQuery tables.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcp Toolbox For Databases
Mcp-Toolbox