Skip to content
mcp-toolboxGHSA-vwxw-jrg6-9jxv

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints

Critical9.1CVE-2026-11720 · Published Jun 29, 2026 · updated Sep 10, 2026

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While it checks that the input does not alter the scheme, host, or user info, it relies on ResolveReference for the final URL resolution. Because dot segments (../) are normalized during this resolution step, an attacker can supply path parameters containing directory traversal sequences to escape the operator-configured path scope. This allows the client to coerce the toolbox into making requests to unintended endpoints on the same target host while forwarding the toolbox's configured credentials (e.g., bypassing a restricted path like /api/v1/users/{{.id}} to reach /admin/secrets).

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/googleapis/mcp-toolbox
Go
< 1.3.01.3.0
Details and references

More mcp-toolbox advisories

All mcp-toolbox
Advisory
MCP Toolbox for Databases: authenticated authorization bypass
HighJun 18
mcp-toolbox: authentication bypass
CriticalJun 18
mcp-toolbox: authentication bypass
CriticalJun 18
MCP Toolbox for Databases has an Origin Validation Error
CriticalJun 13
MCP Toolbox for Databases vulnerable to DNS rebinding attacks
CriticalMay 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.