PT-2026-65097 · Google+1 · Mcp Toolbox For Databases+1

·

CVE-2026-16481

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v4.0

6.0

Medium

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions googleapis/mcp-toolbox (affected versions not specified)
Description A Server-Side Request Forgery (SSRF) and credential exfiltration issue exists in the cloud-healthcare-fhir-fetch-page tool. The tool processes an unvalidated pageURL parameter from the client to issue an HTTP GET request using an authenticated client. Because the underlying transport automatically attaches an Authorization: Bearer header to all outbound requests regardless of the destination host, an attacker can provide an arbitrary external URL via the pageURL parameter. This causes the tool to send its OAuth or service-account access token to an attacker-controlled listener, potentially exposing Protected Health Information (PHI) and other Google Cloud Platform services.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the pageURL parameter in the cloud-healthcare-fhir-fetch-page tool until the issue is resolved.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16481

Affected Products

Mcp Toolbox For Databases
Mcp-Toolbox