CVE-2026-11624Critical▾ MidnightMCP Toolbox for Databases has an Origin Validation Error
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.2%
Last analysed / modified upstream
The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. In v0.25.0, a new "--allowed-hosts" flag was introduced alongside the existing "--allowed-origins" flag, enabling users to specify permitted hosts at server startup. Both flags default to "", allowing users to implement strict access controls as needed without breaking existing setups. If either flag is set to "", the server will output a startup warning about potential vulnerabilities. Documentation has also been updated to highlight these security considerations.
github.com/googleapis/mcp-toolbox < 0.25.0Upgrade to a patched release:
github.com/googleapis/mcp-toolbox 0.25.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-11720Critical· 9.1MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
CVE-2026-11717Criticalgoogleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
CVE-2026-11718Criticalgoogleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
CVE-2026-11719HighMCP Toolbox for Databases: authenticated authorization bypass