VYPR

bigquery-forecast

by Google

CVEs (1)

  • CVE-2026-15829Jul 21, 2026
    risk 0.00cvss epss 0.00

    A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings…