CVE-2026-102242

Source
https://cve.org/CVERecord?id=CVE-2026-102242
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102242.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-102242
Published
2026-09-29T17:47:16Z
Modified
2026-10-01T03:47:29Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Path Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for Databases
Details

Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.

Database specific
{
    "cna_assigner":  "Google",
    "cwe_ids":  [
        "CWE-22",
        "CWE-59"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102242.json"
}
References

Affected packages

Git / github.com/googleapis/mcp-toolbox

Affected ranges

Type
GIT
Repo
https://github.com/googleapis/mcp-toolbox
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "1.2.0"
        },
        {
            "last_affected":  "1.9.0"
        },
        {
            "fixed":  "1.9.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

v1.*
v1.2.0
v1.3.0
v1.4.0
v1.5.0
v1.6.0
v1.7.0
v1.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102242.json"