Skip to content
GoogleCVE-2026-14541

Google mcp-toolbox: authentication bypass

High8.0CVE-2026-14541 · Published Jul 31, 2026 · updated Aug 8, 2026

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation entirely. As a result, the toolbox will accept any valid Google OAuth access token—even those minted for unrelated ecosystem applications—granting unauthorized clients access to protected tools and data backends.

Google advisory

Affected versions

PackageAffectedFixed in
mcp-toolbox
Product
<= 1.4.0No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-287

More Google advisories

All Google
Advisory
Google mcp-toolbox: server-side request forgery
High8.0Jul 31
Google mcp-toolbox: improper authorization
Medium5.7Jul 31
Google mcp-toolbox: denial of service
Medium6.6Jul 31
Google mcp-toolbox: improper authorization
High8.1Jul 31
Google Chrome: spoofing
Medium4.3Jul 30
Google Chrome: remote attacker could bypass navigation restrictions
Medium6.5Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.