CVE-2026-102242: Path Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for Databases

Published Sep 29, 2026
·
Updated

Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.

Affected Software

1 affected component
Google Mcp Toolbox For Databases>=1.2.0<=1.9.0

Event History

Sep 29, 2026
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A remote authenticated attacker needs tool execution permissions. The issue affects deployments using the allowedLocalRoots path restriction in versions 1.2.0 through 1.9.0.

2

What access could an attacker gain through successful exploitation?

An attacker can bypass the configured permitted-root boundaries by using symbolic links. This can allow access to or overwriting of arbitrary local files outside those root directories.

3

Are systems safe if allowedLocalRoots is configured but symbolic links are present?

No. The validation checks directory paths lexically and does not resolve symbolic links before enforcing the boundary, so symbolic links can point from an allowed root to locations outside it.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203