Server-Side Request Forgery and Credential Exfiltration in Google Cloud Healthcare Tool
CVE-2026-16481

8.4HIGH

What is CVE-2026-16481?

A serious vulnerability exists in the cloud-healthcare-fhir-fetch-page tool that allows for Server-Side Request Forgery (SSRF) and credential exfiltration. This issue arises from the tool's handling of the pageURL parameter, which is not properly validated. This oversight enables an attacker to craft a malicious request that forces the tool to send an HTTP GET request to an arbitrary external URL. As a result, an attacker could receive an OAuth/service-account access token, which poses a risk of disclosing sensitive user information and access to Protected Health Information (PHI). The potential for exposure extends to other Google Cloud Platform services, highlighting the need for security measures to validate outbound requests and protect sensitive credentials.

Affected Version(s)

MCP Toolbox for Databases (googleapis/mcp-toolbox) 0.19.1 <= 1.4.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HE WEI(ギカク)(https://www.linkedin.com/in/gikaku/)
.