CVE-2026-102242

CVE-2026-102242 published: Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrict...

View full NVD advisory → ← Back to CVE watch