2026-09-29 17:47CVE-2026-102242Google
PUBLISHED5.2CWE-59CWE-22

Path Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for Databases

Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.

Problem type

Affected products

Google

MCP Toolbox for Databases

<= 1.9.0 - AFFECTED

References

GitHub Security Advisories

GHSA-3gp8-hjh6-xf3r

Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP...

https://github.com/advisories/GHSA-3gp8-hjh6-xf3r

Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-102242
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-102242",
    "assignerOrgId": "14ed7db2-1595-443d-9d34-6215bf890778",
    "assignerShortName": "Google",
    "dateUpdated": "2026-09-29T17:47:16.184Z",
    "dateReserved": "2026-09-28T18:43:08.600Z",
    "datePublished": "2026-09-29T17:47:16.184Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "14ed7db2-1595-443d-9d34-6215bf890778",
        "shortName": "Google",
        "dateUpdated": "2026-09-29T17:47:16.184Z"
      },
      "title": "Path Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for Databases",
      "descriptions": [
        {
          "lang": "en",
          "value": "Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.</p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Google",
          "product": "MCP Toolbox for Databases",
          "repo": "https://github.com/googleapis/mcp-toolbox",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "1.2.0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "1.9.0"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-59 Improper Link Resolution Before File Access ('Link Following')",
              "cweId": "CWE-59",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
              "cweId": "CWE-22",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/googleapis/mcp-toolbox/pull/3810"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-132",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-132 Symlink Attack"
            }
          ]
        },
        {
          "capecId": "CAPEC-126",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-126 Path Traversal"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Emmanuel David Karganilla",
          "type": "finder"
        }
      ]
    }
  }
}