github.com/googleapis/mcp-toolbox
MCP Toolbox for Databases is an open source MCP server for databases.
Activity
- Latest release
- 3d ago
- Total releases
- 23
- Cadence
- ~13 days
- Last 12 months
- 23
Reach
- Stars
- 16.4k
Details
- First release
- Dec 05, 2025
| Version | Released | |
|---|---|---|
v1.11.0
minor
|
v1.11.0
minor
Dependencies (81)
+ 73 more |
|
v1.10.0
minor
|
v1.10.0
minor
Dependencies (79)
+ 71 more |
|
v1.9.0
minor
|
v1.9.0
minor
Dependencies (78)
+ 70 more |
|
v1.8.0
minor
|
v1.8.0
minor
Dependencies (77)
+ 69 more |
|
v1.7.0
minor
|
v1.7.0
minor
Dependencies (75)
+ 67 more |
|
v1.6.0
minor
|
v1.6.0
minor
Dependencies (74)
+ 66 more |
|
v1.5.0
minor
|
v1.5.0
minor
Dependencies (74)
+ 66 more |
|
v1.4.0
minor
|
v1.4.0
minor
Dependencies (72)
+ 64 more |
|
v1.3.0
minor
3 CVEs
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.3.0
minor
Dependencies (71)
+ 63 more |
|
v1.2.0
minor
4 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (71)
+ 63 more |
|
v1.1.0
minor
5 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-9739
GO-2026-5870
GHSA-7pf3-8xx7-rvhf
Jul 07, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox Fixed in
1.2.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (70)
+ 62 more |
|
v1.0.0
major
5 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-9739
GO-2026-5870
GHSA-7pf3-8xx7-rvhf
Jul 07, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox Fixed in
1.2.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.0
major
Dependencies (70)
+ 62 more |
|
v0.32.0
minor
5 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-9739
GO-2026-5870
GHSA-7pf3-8xx7-rvhf
Jul 07, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox Fixed in
1.2.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.32.0
minor
Dependencies (70)
+ 62 more |
|
v0.31.0
minor
5 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-9739
GO-2026-5870
GHSA-7pf3-8xx7-rvhf
Jul 07, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox Fixed in
1.2.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.31.0
minor
Dependencies (70)
+ 62 more |
|
v0.30.0
minor
5 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-9739
GO-2026-5870
GHSA-7pf3-8xx7-rvhf
Jul 07, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox Fixed in
1.2.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.30.0
minor
Dependencies (66)
+ 58 more |
|
v0.29.0
minor
5 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-9739
GO-2026-5870
GHSA-7pf3-8xx7-rvhf
Jul 07, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox Fixed in
1.2.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.29.0
minor
Dependencies (65)
+ 57 more |
|
v0.28.0
minor
5 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-9739
GO-2026-5870
GHSA-7pf3-8xx7-rvhf
Jul 07, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox Fixed in
1.2.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.28.0
minor
Dependencies (64)
+ 56 more |
|
v0.27.0
minor
5 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-9739
GO-2026-5870
GHSA-7pf3-8xx7-rvhf
Jul 07, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox Fixed in
1.2.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.27.0
minor
Dependencies (64)
+ 56 more |
|
v0.26.0
minor
5 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-9739
GO-2026-5870
GHSA-7pf3-8xx7-rvhf
Jul 07, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox Fixed in
1.2.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.26.0
minor
Dependencies (60)
+ 52 more |
|
v0.25.0
minor
5 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-9739
GO-2026-5870
GHSA-7pf3-8xx7-rvhf
Jul 07, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox Fixed in
1.2.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.25.0
minor
Dependencies (60)
+ 52 more |
|
v0.24.0
minor
6 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-9739
GO-2026-5870
GHSA-7pf3-8xx7-rvhf
Jul 07, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox Fixed in
1.2.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11624
GHSA-76g7-m3xw-x9gr
GO-2026-6288
Jun 13, 2026
MCP Toolbox for Databases has an Origin Validation Error
Critical
Network
Low
None
The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. In v0.25.0, a new "--allowed-hosts" flag was introduced alongside the existing "--allowed-origins" flag, enabling users to specify permitted hosts at server startup. Both flags default to "", allowing users to implement strict access controls as needed without breaking existing setups. If either flag is set to "", the server will output a startup warning about potential vulnerabilities. Documentation has also been updated to highlight these security considerations. Fixed in
0.25.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.24.0
minor
Dependencies (58)
+ 50 more |
|
v0.23.0
minor
6 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-9739
GO-2026-5870
GHSA-7pf3-8xx7-rvhf
Jul 07, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox Fixed in
1.2.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11624
GHSA-76g7-m3xw-x9gr
GO-2026-6288
Jun 13, 2026
MCP Toolbox for Databases has an Origin Validation Error
Critical
Network
Low
None
The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. In v0.25.0, a new "--allowed-hosts" flag was introduced alongside the existing "--allowed-origins" flag, enabling users to specify permitted hosts at server startup. Both flags default to "", allowing users to implement strict access controls as needed without breaking existing setups. If either flag is set to "", the server will output a startup warning about potential vulnerabilities. Documentation has also been updated to highlight these security considerations. Fixed in
0.25.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.23.0
minor
Dependencies (57)
+ 49 more |
|
v0.22.0
initial
6 CVEs
CVE-2026-11720
GO-2026-6411
GHSA-vwxw-jrg6-9jxv
Sep 10, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox Fixed in
1.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-9739
GO-2026-5870
GHSA-7pf3-8xx7-rvhf
Jul 07, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases vulnerable to DNS rebinding attacks in github.com/googleapis/mcp-toolbox Fixed in
1.2.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-11718
GO-2026-5706
GHSA-wcpr-6g7x-p44r
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11717
GO-2026-5251
GHSA-8fcc-w5hv-4gxv
Jun 25, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11719
GO-2026-5144
GHSA-5gf6-gc35-xjpc
Jun 25, 2026
MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox MCP Toolbox for Databases: authenticated authorization bypass in github.com/googleapis/mcp-toolbox Fixed in
1.4.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-11624
GHSA-76g7-m3xw-x9gr
GO-2026-6288
Jun 13, 2026
MCP Toolbox for Databases has an Origin Validation Error
Critical
Network
Low
None
The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. In v0.25.0, a new "--allowed-hosts" flag was introduced alongside the existing "--allowed-origins" flag, enabling users to specify permitted hosts at server startup. Both flags default to "", allowing users to implement strict access controls as needed without breaking existing setups. If either flag is set to "", the server will output a startup warning about potential vulnerabilities. Documentation has also been updated to highlight these security considerations. Fixed in
0.25.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.22.0
initial
Dependencies (57)
+ 49 more |