CVE-2026-102242: CWE-59 Improper Link Resolution Before File Access ('Link Following') in Google MCP Toolbox for Databases
Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.
AI Analysis
Technical Summary
This vulnerability (CWE-59 / CWE-22) arises from improper link resolution in the allowedLocalRoots path validation mechanism of Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0. The path validation performs lexical checks on directory paths without resolving symbolic links beforehand. Consequently, a remote authenticated attacker with execution permissions on the tool can exploit symbolic links to bypass directory boundary restrictions, enabling unauthorized access or overwriting of arbitrary local files outside the allowed root directories.
Potential Impact
An attacker with authenticated access and tool execution permissions can bypass directory boundary restrictions, potentially accessing or modifying arbitrary files on the local filesystem outside the intended allowed directories. This could lead to unauthorized data disclosure or data tampering. The CVSS 4.0 base score is 8.6 (high severity), reflecting network attack vector, low attack complexity, no user interaction, and high impact on confidentiality and integrity.
Mitigation Recommendations
No official patch or remediation details are provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict tool execution permissions to trusted users only and monitor for suspicious activity related to symbolic link usage.
CVE-2026-102242: CWE-59 Improper Link Resolution Before File Access ('Link Following') in Google MCP Toolbox for Databases
Description
Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.
CVSS v4.0
Score 8.6high
Affected software
MCP Toolbox for Databases
pkg:github/MCP Toolbox for DatabasesRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-59 / CWE-22) arises from improper link resolution in the allowedLocalRoots path validation mechanism of Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0. The path validation performs lexical checks on directory paths without resolving symbolic links beforehand. Consequently, a remote authenticated attacker with execution permissions on the tool can exploit symbolic links to bypass directory boundary restrictions, enabling unauthorized access or overwriting of arbitrary local files outside the allowed root directories.
Potential Impact
An attacker with authenticated access and tool execution permissions can bypass directory boundary restrictions, potentially accessing or modifying arbitrary files on the local filesystem outside the intended allowed directories. This could lead to unauthorized data disclosure or data tampering. The CVSS 4.0 base score is 8.6 (high severity), reflecting network attack vector, low attack complexity, no user interaction, and high impact on confidentiality and integrity.
Mitigation Recommendations
No official patch or remediation details are provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict tool execution permissions to trusted users only and monitor for suspicious activity related to symbolic link usage.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Date Reserved
- 2026-09-28T18:43:08.600Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abbfcc9107c4a03cbb28016
Added to database: 09/29/2026, 18:00:41 UTC
Last enriched: 09/29/2026, 18:01:19 UTC
Last updated: 09/29/2026, 18:51:53 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.