Server-Side Request Forgery in Google MCP Toolbox
CVE-2026-14540
8HIGH
What is CVE-2026-14540?
A vulnerability in Google MCP Toolbox allows attackers to exploit improper request handling mechanisms. Due to insufficient validation of redirection boundaries within the HTTP client, an attacker can manipulate crafted input to trigger unauthorized requests to both internal and external endpoints. This vulnerability arises from the lack of a restrictive CheckRedirect policy and insufficient target IP validation, which can lead to an open redirect situation. As a result, users of affected versions are at risk of having their systems misdirected and threatened by potential unauthorized access.
Affected Version(s)
mcp-toolbox 0.3.0 <= 1.4.0