Skip to content
GoogleCVE-2026-102242

Google MCP Toolbox for Databases: path traversal

High8.6CVE-2026-102242 · Published Sep 29, 2026

Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.

Google advisory

Affected versions

PackageAffectedFixed in
MCP Toolbox for Databases
Product
>= 1.2.0, <= 1.9.0No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-22, CWE-59

More Google advisories

All Google
Advisory
Google Chrome: improper authorization
High7.5Sep 29
Google Chrome: type confusion
High8.8Sep 29
Google Chrome: cross-site scripting
Medium6.1Sep 29
Google Chrome: improper authorization
Medium6.5Sep 29
Google Chrome: buffer overflow
Critical9.6Sep 29
Google Chrome: out-of-bounds read
Medium4.7Sep 29

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.