PT-2026-97091 · Pypi · Mcp-Toolbox-Sdk-Python

·

CVE-2026-19202

·

Published

2026-09-22

·

Updated

2026-10-01

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions mcp-toolbox-sdk-python (affected versions not specified)
Description A caching flaw in the toolbox-core package allows a Google ID token to be cached and reused across different audiences within the same process. The module-level token cache fails to key cached tokens by the requested audience, which can lead to a token minted for a sensitive service being retrieved and sent to a secondary service. An attacker who controls or monitors traffic to the secondary service can capture this token and replay it to impersonate the victim application against the sensitive service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19202

Affected Products

Mcp-Toolbox-Sdk-Python