漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox
Vulnerability Description
A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to safely regulate request redirection boundaries. Specifically, the client is initialized without a restrictive CheckRedirect policy hook and lacks target IP validation. An attacker or a malicious data-driven prompt can supply a crafted path parameter that triggers an open redirect or a direct destination swap on the target backend, coercing the mcp-toolbox into blindly following the redirection and making unauthorized requests to internal or arbitrary external endpoints.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Google MCP Toolbox for Databases 服务端请求伪造漏洞
Vulnerability Description
Google MCP Toolbox for Databases是美国Google公司的数据库管理工具。 Google MCP Toolbox for Databases 0.3.0版本至1.4.0版本存在服务端请求伪造漏洞,该漏洞源于generic HTTP source和tool components组件中的HTTP客户端未安全限制请求重定向边界且缺少目标IP校验,可能导致攻击者利用特制路径参数触发重定向,向内部或任意外部端点发起未授权请求(服务端请求伪造)。
CVSS Information
N/A
Vulnerability Type
N/A