Vulnerability Description
A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While it checks that the input does not alter the scheme, host, or user info, it relies on ResolveReference for the final URL resolution. Because dot segments (../) are normalized during this resolution step, an attacker can supply path parameters containing directory traversal sequences to escape the operator-configured path scope. This allows the client to coerce the toolbox into making requests to unintended endpoints on the same target host while forwarding the toolbox's configured credentials (e.g., bypassing a restricted path like /api/v1/users/{{.id}} to reach /admin/secrets).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcp Toolbox For Databases | < 1.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/googleapis/mcp-toolbox/pull/3218Issue TrackingPatch
FAQ
What is CVE-2026-11720?
CVE-2026-11720 is a vulnerability with a CVSS score of 9.1 (CRITICAL). A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into th...
How severe is CVE-2026-11720?
CVE-2026-11720 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-11720?
Check the references section above for vendor advisories and patch information. Affected products include: Google Mcp Toolbox For Databases.