Google MCP Toolbox CVE-2026-14540 SSRF (CVSS 4.0 8.0) — HTTP source redirect; fixed 1.5.0+
CVE-2026-14540 (CNA: Google LLC; published 31 July 2026; researcher write-up amplified on HN 28 Sep 2026) is a server-side request forgery in the generic HTTP source/tool components of Google mcp-toolbox (MCP Toolbox for Databases) versions 0.3.0 through 1.4.0. The Go HTTP client lacked a restrictive CheckRedirect policy and target IP validation, so a crafted path parameter (including via a malicious data-driven prompt to a connected agent) could coerce redirects to internal or arbitrary endpoints (CWE-918). Google CVSS 4.0 base 8.0 HIGH: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U. Fixed in mcp-toolbox 1.5.0+ via SSRFGuard (GitHub PR #3448 — DNS-rebinding/TOCTOU protection, IP allow/block lists, base-URL fail-fast). Credited: Syed Anas Mohiuddin. No public in-the-wild exploitation stated on the CVE record. Primary: CVE.org / Google PR; wire: researcher post / HN 28 Sep.
- Product
- Google mcp-toolbox (MCP Toolbox for Databases)
- Versions
- Affected: 0.3.0 through 1.4.0. Fixed: 1.5.0 and later (SSRFGuard in PR #3448).
- CVSS
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N- Exploited in Australia?
- unknown
- Patch to
- Upgrade mcp-toolbox to 1.5.0 or later. Until then, restrict egress from the host (block link-local/metadata and RFC1918 as appropriate), avoid exposing the toolbox to untrusted networks, and audit HTTP source/tool path parameters for untrusted input.
Primary: CVE.org — CVE-2026-14540 (Google mcp-toolbox SSRF; 31 Jul 2026) · Vendor: googleapis/mcp-toolbox PR #3448 — SSRFGuard fix · CVE: CVE-2026-14540 · Researcher write-up — CVE-2026-14540 / MCP dependency scanning gap (HN 28 Sep 2026)
