CVE-2026-19202: CWE-524: Use of a Shared Cache with Insufficient Key Granularity in Google mcp-toolbox-sdk-python
A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. If an application uses the SDK to authenticate to two or more different audiences within the same process, the module-level token cache fails to key its cached tokens by the requested audience. Consequently, a valid, unexpired token minted for a sensitive service (Service A) can be retrieved from the cache and sent to a secondary service (Service B). An attacker who operates, compromises, or monitors traffic to Service B can capture this token and replay it to impersonate the victim application against Service A.
AI Analysis
Technical Summary
The vulnerability arises from a caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK. The module-level token cache does not differentiate cached tokens by audience, causing the same valid, unexpired Google ID token minted for one service (Service A) to be reused and sent to another service (Service B). This allows an attacker who operates or compromises Service B to capture the token and replay it to impersonate the victim application against Service A. The issue is classified as CWE-524 (Use of a Shared Cache with Insufficient Key Granularity).
Potential Impact
An attacker who controls or monitors traffic to a secondary service can capture a token intended for a sensitive service and replay it to impersonate the victim application against that sensitive service. This can lead to unauthorized access and potential compromise of sensitive services relying on the SDK for authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a fix is available, avoid using the SDK to authenticate to multiple audiences within the same process or implement custom token caching keyed by audience to prevent token reuse across audiences.
CVE-2026-19202: CWE-524: Use of a Shared Cache with Insufficient Key Granularity in Google mcp-toolbox-sdk-python
Description
A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. If an application uses the SDK to authenticate to two or more different audiences within the same process, the module-level token cache fails to key its cached tokens by the requested audience. Consequently, a valid, unexpired token minted for a sensitive service (Service A) can be retrieved from the cache and sent to a secondary service (Service B). An attacker who operates, compromises, or monitors traffic to Service B can capture this token and replay it to impersonate the victim application against Service A.
CVSS v4.0
Score 9.1critical
Affected software
mcp-toolbox-sdk-python
pkg:pypi/mcp-toolbox-sdk-pythonRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from a caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK. The module-level token cache does not differentiate cached tokens by audience, causing the same valid, unexpired Google ID token minted for one service (Service A) to be reused and sent to another service (Service B). This allows an attacker who operates or compromises Service B to capture the token and replay it to impersonate the victim application against Service A. The issue is classified as CWE-524 (Use of a Shared Cache with Insufficient Key Granularity).
Potential Impact
An attacker who controls or monitors traffic to a secondary service can capture a token intended for a sensitive service and replay it to impersonate the victim application against that sensitive service. This can lead to unauthorized access and potential compromise of sensitive services relying on the SDK for authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a fix is available, avoid using the SDK to authenticate to multiple audiences within the same process or implement custom token caching keyed by audience to prevent token reuse across audiences.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Date Reserved
- 2026-08-07T05:27:47.674Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab2fb2ff7a7c54106d75aa6
Added to database: 09/22/2026, 22:03:27 UTC
Last enriched: 09/22/2026, 22:17:38 UTC
Last updated: 09/23/2026, 02:44:34 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.