Server-Side Request Forgery in Google MCP Toolbox
CVE-2026-14540

8HIGH

Key Information:

Vendor

Google

Vendor
CVE Published:
31 July 2026

What is CVE-2026-14540?

A vulnerability in Google MCP Toolbox allows attackers to exploit improper request handling mechanisms. Due to insufficient validation of redirection boundaries within the HTTP client, an attacker can manipulate crafted input to trigger unauthorized requests to both internal and external endpoints. This vulnerability arises from the lack of a restrictive CheckRedirect policy and insufficient target IP validation, which can lead to an open redirect situation. As a result, users of affected versions are at risk of having their systems misdirected and threatened by potential unauthorized access.

Affected Version(s)

mcp-toolbox 0.3.0 <= 1.4.0

References

CVSS V4

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Syed Anas Mohiuddin
.