---
id: CVE-2026-102242
title: >-
  Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path
  validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0
  allows a remote authenticated attacker with tool execution permissions to
  bypass directo…
summary: >-
  Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path
  validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0
  allows a remote authenticated attacker with tool execution permissions to
  bypass directo…
severity: high
cvss: 8.6
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-22
  - CWE-59
vendor: Google
product: MCP Toolbox for Databases
affected:
  - mcp_toolbox_for_databases >= 1.2.0 <= 1.9.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:17:19.467'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102242'
references:
  - url: 'https://github.com/googleapis/mcp-toolbox/pull/3810'
    label: cve-coordination@google.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-29T18:35:00.989571Z'
cvssSource: cna
ingestedAt: '2026-09-29T18:42:35.811Z'
---

## Overview

Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
