---
id: CVE-2026-11717
title: >-
  googleapis/mcp-toolbox: authentication bypass vulnerability in the generic
  opaque token validation path (validateOpaqueToken)
summary: >-
  googleapis/mcp-toolbox: authentication bypass vulnerability in the generic
  opaque token validation path (validateOpaqueToken)
severity: critical
cwe:
  - CWE-287
vendor: googleapis
product: github.com/googleapis/mcp-toolbox
ecosystem: go
affected:
  - github.com/googleapis/mcp-toolbox < 1.4.0
patched:
  - github.com/googleapis/mcp-toolbox 1.4.0
published: '2026-06-18'
updated: '2026-06-19'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-8fcc-w5hv-4gxv'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11717'
  - url: 'https://github.com/googleapis/mcp-toolbox/pull/3341'
  - url: 'https://github.com/advisories/GHSA-8fcc-w5hv-4gxv'
tags:
  - ghsa
  - go
epss: 0.00176
epssPercentile: 0.06421
ingestedAt: '2026-06-29T14:31:46.958Z'
---

## Overview

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox.

When verifying an unparsed opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), the toolbox decodes the response into an introspectResp struct where the Active field is declared as a pointer to a boolean (*bool). The code only explicitly rejects a token if the response contains a populated active field set to false (if introspectResp.Active != nil && !*introspectResp.Active). If an introspection endpoint responds with a payload that completely omits the mandatory active key, the internal variable remains nil, causing the conditional check to short-circuit. As a result, Toolbox accepts authorization tokens missing the "active" field, granting access to protected tools and underlying data sources.

## Affected packages

- `github.com/googleapis/mcp-toolbox < 1.4.0`

## Remediation

Upgrade to a patched release:

- `github.com/googleapis/mcp-toolbox 1.4.0`
