CyberRota Analysis
AI-GeneratedThe vulnerability arises from improper link resolution in the allowedLocalRoots path validation within Google MCP Toolbox for Databases versions 1.2.0 to 1.9.0, allowing remote authenticated attackers with tool execution permissions to bypass directory restrictions through symbolic links. This flaw enables attackers to access or overwrite arbitrary local files outside of designated root directories, posing a significant risk to data integrity and confidentiality. Organizations using affected versions should prioritize remediation to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.