UNKNOWN Go
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox
GO-2026-6411 · CVE-2026-11720 · GHSA-vwxw-jrg6-9jxv
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox
References
- ADVISORY https://github.com/advisories/GHSA-vwxw-jrg6-9jxv
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-11720
- FIX https://github.com/googleapis/mcp-toolbox/commit/80a66021205e032a424fff87b3dc6d92da58aa77
- FIX https://github.com/googleapis/mcp-toolbox/pull/3218
- WEB https://github.com/googleapis/mcp-toolbox/releases/tag/v1.3.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes