CVE-2026-102242: Path Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for Databases
Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote authenticated attacker needs tool execution permissions. The issue affects deployments using the allowedLocalRoots path restriction in versions 1.2.0 through 1.9.0.
What access could an attacker gain through successful exploitation?
An attacker can bypass the configured permitted-root boundaries by using symbolic links. This can allow access to or overwriting of arbitrary local files outside those root directories.
Are systems safe if allowedLocalRoots is configured but symbolic links are present?
No. The validation checks directory paths lexically and does not resolve symbolic links before enforcing the boundary, so symbolic links can point from an allowed root to locations outside it.