Threat · curated 28 Sep 2026
An SSRF in Google's MCP Toolbox
First reported anas-security-portfolio.vercel.app
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
CVE-2026-14540 shows that MCP tool servers embedded in production AI systems introduce SSRF and other attack surface that conventional dependency-scanning cannot see, exposing internal endpoints to attackers who can influence prompts.
An independent researcher disclosed CVE-2026-14540, a server-side request forgery (CVSS 8.0) in Google's official MCP Toolbox for Databases, where the HTTP client lacked a CheckRedirect policy and target-IP validation, so a crafted path parameter could redirect the toolbox into making requests to internal endpoints on behalf of whoever controlled the prompt. Google fixed it in googleapis/mcp-toolbox PR #3448 with DNS-rebinding/TOCTOU protection and IP allow/block lists. The write-up also argues that MCP tool servers form a new dependency class that standard SCA tools cannot analyze, and references a scanner (mcp-safeguard) that found the bug.
Summary
An independent researcher, Anas Mohiuddin Syed, disclosed CVE-2026-14540, a server-side request forgery (SSRF) vulnerability in Google's official MCP Toolbox for Databases, rated CVSS 8.0. The vulnerability was coordinated-disclosed to Google, fixed in PR #3448, and the researcher was credited by name.[0]
The root cause is that the toolbox's HTTP client was initialized without a CheckRedirect policy and without target IP validation, so a crafted path parameter could redirect the toolbox into making requests against internal endpoints on behalf of whoever controlled the prompt. The write-up frames the finding as evidence of a broader blind spot: MCP tool servers are a new dependency class that standard software-composition-analysis tooling cannot reach because analysis stops at the JSON-RPC transport boundary.[0]
Disclosure timeline
| Date | Event |
|---|---|
| 2026-07-03 | CVE-2026-14540 reserved by Google[0] |
| 2026-07-31 | Vulnerability published at CVSS 8.0 and fixed in googleapis/mcp-toolbox PR #3448, with the researcher credited by name[0] |
How it works
The MCP Toolbox for Databases HTTP client was initialized without a CheckRedirect policy and without target IP validation. As a result, a crafted path parameter could cause the toolbox to follow a redirect and issue requests to internal endpoints on behalf of whoever controlled the prompt — a classic SSRF primitive.[0]
The researcher argues this class of flaw is invisible to traditional software composition analysis: an MCP server is invoked over stdio or HTTP via JSON-RPC, so the application never calls the server's functions directly and the call graph stops at the transport boundary. The remediation implements a real SSRF guard including DNS-rebinding/TOCTOU protection, IP-range allow/block lists, and fail-fast base-URL validation.[0]
Affected versions and patch status
| Product | Affected | Patch status |
|---|---|---|
| Google MCP Toolbox for Databases (googleapis/mcp-toolbox) | Versions prior to the fix for CVE-2026-14540 | Fixed on 2026-07-31 in PR #3448[0] |
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| cve | CVE-2026-14540 | Identifier assigned by Google for the SSRF in the MCP Toolbox for Databases, CVSS 8.0[0][2] |
Key takeaways
- MCP tool servers represent a rapidly deployed dependency class that has received little adversarial attention and is largely invisible to traditional software-composition-analysis reachability tooling, which stops at the JSON-RPC transport boundary.[0]
- For MCP, the researcher argues exposure should be treated as equivalent to reachability: anything in the served tool manifest should be assumed reachable, with risk reduced only by controls outside the model such as allowlists, scopes, and human confirmation.[0]
- A simple static-analysis rule over tool manifests and handlers surfaced a CVSS 8.0 SSRF in Google's own toolbox, underscoring how under-examined this category currently is.[0]
Defensive actions
- Upgrade the Google MCP Toolbox for Databases to the release containing PR #3448: The patch adds an SSRF guard with DNS-rebinding/TOCTOU protection, IP-range allow/block lists, and fail-fast base-URL validation, remediating the redirect-based SSRF[0]
- Treat MCP tool servers as a first-class dependency class and audit their served tool manifests and handlers directly: Standard software-composition-analysis reachability engines cannot see past the JSON-RPC transport boundary, so exposure in the served manifest should be assumed reachable and reviewed with dedicated tooling[0]