What happened
NVD published CVE-2026-102242 (CVSS 8.6 HIGH, CVSS v4.0) on 2026-09-29, coordinated by Google. Path validation in the MCP Toolbox for Databases checks directories lexically without resolving symlinks first (CWE-22/CWE-59), so a remote authenticated attacker with tool execution permissions escapes the restricted roots via symbolic links to read or write arbitrary local files outside the permitted directories.
Why it matters
MCP Toolbox for Databases is Google's sanctioned MCP server for letting LLM agents query databases; the allowedLocalRoots boundary is the sandbox that keeps a database agent from touching the host filesystem. A symlink traversal breaks that boundary, letting a prompt-injected or malicious agent read secrets/keys and overwrite host files (e.g. config, cron, SSH keys) from the trusted DB tool surface.
Attack vector
Remote authenticated attacker with tool-execution permission (an agent or user allowed to run DB MCP tools) supplies paths through symlinks that are validated lexically, bypassing the allowedLocalRoots directory boundary to access or overwrite arbitrary local files on the host.
Affected systems
Google MCP Toolbox for Databases 1.2.0 through 1.9.0 (github.com/googleapis/mcp-toolbox)
Mitigation
Upgrade to a fixed version (fix in mcp-toolbox PR https://github.com/googleapis/mcp-toolbox/pull/3810); ensure symlink resolution happens before root validation.