Google MCP Toolbox for Databases是美国谷歌(Google)公司的一个开源的模型上下文协议(MCP)服务器。 Google MCP Toolbox for Databases存在安全漏洞,该漏洞源于使用SSE时容易受到DNS重新绑定攻击,且硬编码的Access-Control-Allow-Origin: *标头被无意保留,可能导致安全限制被绕过。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MCP Toolbox for Databases | < PR 3054 (Fix CORS bypass) |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MCP Toolbox for Databases | 0 ~ PR 3054 (Fix CORS bypass) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet