Impact
Improper link resolution in the allowedLocalRoots path validation allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because the validation checks directories lexically without resolving symbolic links first, the attacker can access or overwrite arbitrary local files located outside the permitted root directories, potentially compromising the confidentiality or integrity of the system.
Affected Systems
Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 are affected. The flaw resides in any configuration that uses allowedLocalRoots to restrict local file access.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote authenticated: an attacker who can run the tool with tool execution permissions and manipulate the configuration may exploit the symlink resolution flaw to read or overwrite files outside the permitted root directories.
OpenCVE Enrichment