Caching Flaw in Google APIs Toolkit Affects Multiple Audiences
CVE-2026-19202

9.1CRITICAL

Key Information:

Vendor

Google

Vendor
CVE Published:
22 September 2026

What is CVE-2026-19202?

A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK allows the same Google ID token to be improperly cached and reused across different audiences. When applications authenticate to multiple audiences within the same process using this SDK, the module-level token cache fails to distinguish the cached tokens by the intended audience. This oversight can lead to a valid token, originally issued for a sensitive service, being fetched from the cache and used to authenticate against another service. An adversary who gains access to Service B can exploit this vulnerability by capturing the token and impersonating the original application to Service A.

Affected Version(s)

mcp-toolbox-sdk-python 0 <= 1.1.0

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HE WEI(ギカク)
.