Description
Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.
Published: 2026-09-29
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Unauthorized File Access
Action: Immediate Patch
AI Analysis

Impact

Improper link resolution in the allowedLocalRoots path validation allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because the validation checks directories lexically without resolving symbolic links first, the attacker can access or overwrite arbitrary local files located outside the permitted root directories, potentially compromising the confidentiality or integrity of the system.

Affected Systems

Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 are affected. The flaw resides in any configuration that uses allowedLocalRoots to restrict local file access.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote authenticated: an attacker who can run the tool with tool execution permissions and manipulate the configuration may exploit the symlink resolution flaw to read or overwrite files outside the permitted root directories.

Generated by OpenCVE AI on September 29, 2026 at 22:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an updated version of MCP Toolbox for Databases that contains the fixed path validation.
  • Restrict tool execution permissions so that only trusted users can run the tool.
  • Configure allowedLocalRoots to exclude directories that contain symbolic links pointing outside the permitted scope and monitor for anomalous file access attempts.

Generated by OpenCVE AI on September 29, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google mcp Toolbox For Databases
Vendors & Products Google
Google mcp Toolbox For Databases

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.
Title Path Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for Databases
Weaknesses CWE-22
CWE-59
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Google Mcp Toolbox For Databases
cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2026-09-29T18:35:11.181Z

Reserved: 2026-09-28T18:43:08.600Z

Link: CVE-2026-102242

cve-icon Vulnrichment

Updated: 2026-09-29T18:35:07.620Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:06.887

Modified: 2026-09-29T21:36:39.547

Link: CVE-2026-102242

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:45:18Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')