CVE-2026-11720
Google MCP Toolbox for Databases (googleapis/mcp-toolbox), mcp toolbox for databases 취약점
A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While it checks that the input does not alter the scheme, host, or user info, it relies on ResolveReference for the final URL resolution. Because dot segments (../) are normalized during this resolution step, an attacker can supply path parameters containing directory traversal sequences to escape the operator-configured p...
- 대응 우선순위
- 점검
- CVSS
- 9.3
- EPSS
- 0.38% 백분위 30.9% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.30