High severityNVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026
CVE-2026-102242
CVE-2026-102242
Description
Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 1.2.0-1.9.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.