OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-19202

CRITICAL · CVSS 9.1 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability arises from a caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK, which improperly caches Google ID tokens without distinguishing between different audiences. This allows a valid token intended for a sensitive service to be reused inappropriately for another service, enabling an attacker to impersonate the victim application. Organizations utilizing this SDK for authentication across multiple audiences should prioritize remediation to prevent potential token replay attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19202
Severity
CRITICAL
CVSS
9.1
EPSS
0.25%

Original NVD Description

A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. If an application uses the SDK to authenticate to two or more different audiences within the same process, the module-level token cache fails to key its cached tokens by the requested audience. Consequently, a valid, unexpired token minted for a sensitive service (Service A) can be retrieved from the cache and sent to a secondary service (Service B). An attacker who operates, compromises, or monitors traffic to Service B can capture this token and replay it to impersonate the victim application against Service A.