CVE-2026-102242 - Path Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for Databases
CVE ID :CVE-2026-102242 Published : Sept. 29, 2026, 5:47 p.m. | 28 minutes ago Description :Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool...