VYPR

bigquery-execute-sql tool

by Google

CVEs (1)

  • CVE-2026-14538HigJul 31, 2026
    risk 0.50cvss 7.7epss 0.00

    An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery…