CVE-2026-14540(google / mcp_toolbox_for_databases)

LOWCVSS 6.1 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to safely regulate request redirection boundaries. Specifically, the client is initialized without a restrictive CheckRedirect policy hook and lacks target IP validation. An attacker or a malicious data-driven prompt can supply a crafted path parameter that triggers an open redirect or a direct destination swap on the target backend, coercing the mcp-toolbox into blindly following the redirection and making unauthorized requests to internal or arbitrary external endpoints.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp_toolbox_for_databases

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Affected systems

Vendors
Products
mcp_toolbox_for_databases

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-10-06: 310-06
Referenced assets1 URL
Full discourse3 posts
  • TechSignal@tchsignal

    MCP Security Risks Grow as AI Agents Start Trusting Other Agents A newly examined set of vulnerabilities shows why AI-agent security becomes harder when one system starts trusting another. Google's MCP Toolbox for Databases had an SSRF flaw, CVE-2026-14540, rated 8.0 High by Google and fixed through an SSRF guard in version 1.5.0. Rapid7's Bulk Export MCP separately had a low-severity GraphQL query-injection flaw, CVE-2026-97228, fixed in version 0.6.2. These are different implementation bugs, not proof that MCP itself contains one universal vulnerability. The broader concern is how agents, tools and protocols are chained together. Researcher Syed Anas Mohiuddin describes one such cross-protocol pattern as Protocol Pivoting: malicious instructions can enter one agent, pass through MCP tool use or another delegation layer, and reach downstream agents that may inherit too much trust. NSA and Microsoft have separately warned about related risks including prompt injection, unsafe tool chaining and insufficient policy enforcement around agent actions. The security challenge is therefore larger than patching individual CVEs. As multi-agent systems become more interconnected, each trust boundary must be validated rather than assumed. #MCP #AISecurity

    5000081
    38 followersView on X
  • Fenz AI - 🏥 for Agents@fenzlabs

    Google's instance: CVE-2026-14540 (CVSS 8.0), MCP Toolbox for Databases 0.3.0–1.4.0. No redirect policy, no IP checks; the fix added DNS-rebinding guards and IP allow/block lists. Agents trust internal peers, so a prompt injection in one agent can propagate to others.

    2000050
    233 followersView on X
  • AI Cyber Brief@justelite

    Google (CVE-2026-14540), JPMorgan, Weaviate and France's DINUM fixed the same SSRF in their MCP servers, all found by one researcher. Five US GSA MCP servers, incl. one for VA claims, are still unfixed. Unrelated teams, same bug: that's a pattern problem. https://thenextweb.com/news/mcp-flaw-ssrf-google-jpmorgan-dinum-protocol-pivoting

    0000026
    1.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglemcp_toolbox_for_databases---

Explore more