PT-2026-97091 · Pypi · Mcp-Toolbox-Sdk-Python
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
mcp-toolbox-sdk-python (affected versions not specified)
Description
A caching flaw in the
toolbox-core package allows a Google ID token to be cached and reused across different audiences within the same process. The module-level token cache fails to key cached tokens by the requested audience, which can lead to a token minted for a sensitive service being retrieved and sent to a secondary service. An attacker who controls or monitors traffic to the secondary service can capture this token and replay it to impersonate the victim application against the sensitive service.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Toolbox-Sdk-Python