Vulnerability  ·  2026-09-30

Google MCP Toolbox for Databases symlink path traversal escapes allowedLocalRoots to read/overwrite arbitrary files

VulnerabilityHigh impactGlobalCVE-2026-102242
NVD published CVE-2026-102242 (CVSS 8.6 HIGH, CVSS v4.0) on 2026-09-29, coordinated by Google. Path validation in the MCP Toolbox for Databases checks directories lexically without resolving symlinks first (CWE-22/CWE-59), so a remote authenticated attacker with tool execution permissions escapes the restricted roots via symbolic links to read or write arbitrary local files outside the permitted directories.
MCP Toolbox for Databases is Google's sanctioned MCP server for letting LLM agents query databases; the allowedLocalRoots boundary is the sandbox that keeps a database agent from touching the host filesystem. A symlink traversal breaks that boundary, letting a prompt-injected or malicious agent read secrets/keys and overwrite host files (e.g. config, cron, SSH keys) from the trusted DB tool surface.
Remote authenticated attacker with tool-execution permission (an agent or user allowed to run DB MCP tools) supplies paths through symlinks that are validated lexically, bypassing the allowedLocalRoots directory boundary to access or overwrite arbitrary local files on the host.
Google MCP Toolbox for Databases 1.2.0 through 1.9.0 (github.com/googleapis/mcp-toolbox)
Upgrade to a fixed version (fix in mcp-toolbox PR https://github.com/googleapis/mcp-toolbox/pull/3810); ensure symlink resolution happens before root validation.
NVD CVE-2026-102242Google mcp-toolbox PR 3810
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →