Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints
Vulnerability Description
Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Vulnerability Type
授权机制不正确
Vulnerability Title
Google MCP Toolbox for Databases 授权问题漏洞
Vulnerability Description
Google MCP Toolbox for Databases是美国Google公司的数据库管理工具。 Google MCP Toolbox for Databases v1.3.0版本和v1.4.0版本存在授权问题漏洞,该漏洞源于直接HTTP API工具调用端点存在授权不正确问题,可能导致未经身份验证的攻击者在--enable-api标志激活时通过遗留HTTP端点发送工具调用请求来调用受scopeRequired功能保护的工具。
CVSS Information
N/A
Vulnerability Type
N/A