Threat · curated 28 Sep 2026

An SSRF in Google's MCP Toolbox

Dossier

Coverage timeline

28 Sep 2026anas-security-portfolio…

Single-source incident — first reported, latest, and curated coincide.

Why it matters

CVE-2026-14540 shows that MCP tool servers embedded in production AI systems introduce SSRF and other attack surface that conventional dependency-scanning cannot see, exposing internal endpoints to attackers who can influence prompts.

An independent researcher disclosed CVE-2026-14540, a server-side request forgery (CVSS 8.0) in Google's official MCP Toolbox for Databases, where the HTTP client lacked a CheckRedirect policy and target-IP validation, so a crafted path parameter could redirect the toolbox into making requests to internal endpoints on behalf of whoever controlled the prompt. Google fixed it in googleapis/mcp-toolbox PR #3448 with DNS-rebinding/TOCTOU protection and IP allow/block lists. The write-up also argues that MCP tool servers form a new dependency class that standard SCA tools cannot analyze, and references a scanner (mcp-safeguard) that found the bug.

vuln-research

Summary

An independent researcher, Anas Mohiuddin Syed, disclosed CVE-2026-14540, a server-side request forgery (SSRF) vulnerability in Google's official MCP Toolbox for Databases, rated CVSS 8.0. The vulnerability was coordinated-disclosed to Google, fixed in PR #3448, and the researcher was credited by name.[0]

The root cause is that the toolbox's HTTP client was initialized without a CheckRedirect policy and without target IP validation, so a crafted path parameter could redirect the toolbox into making requests against internal endpoints on behalf of whoever controlled the prompt. The write-up frames the finding as evidence of a broader blind spot: MCP tool servers are a new dependency class that standard software-composition-analysis tooling cannot reach because analysis stops at the JSON-RPC transport boundary.[0]

Disclosure timeline

DateEvent
2026-07-03CVE-2026-14540 reserved by Google[0]
2026-07-31Vulnerability published at CVSS 8.0 and fixed in googleapis/mcp-toolbox PR #3448, with the researcher credited by name[0]

How it works

The MCP Toolbox for Databases HTTP client was initialized without a CheckRedirect policy and without target IP validation. As a result, a crafted path parameter could cause the toolbox to follow a redirect and issue requests to internal endpoints on behalf of whoever controlled the prompt — a classic SSRF primitive.[0]

The researcher argues this class of flaw is invisible to traditional software composition analysis: an MCP server is invoked over stdio or HTTP via JSON-RPC, so the application never calls the server's functions directly and the call graph stops at the transport boundary. The remediation implements a real SSRF guard including DNS-rebinding/TOCTOU protection, IP-range allow/block lists, and fail-fast base-URL validation.[0]

Affected versions and patch status

ProductAffectedPatch status
Google MCP Toolbox for Databases (googleapis/mcp-toolbox)Versions prior to the fix for CVE-2026-14540Fixed on 2026-07-31 in PR #3448[0]

Indicators of Compromise

TypeIndicatorContext
cveCVE-2026-14540Identifier assigned by Google for the SSRF in the MCP Toolbox for Databases, CVSS 8.0[0][2]

Key takeaways

  • MCP tool servers represent a rapidly deployed dependency class that has received little adversarial attention and is largely invisible to traditional software-composition-analysis reachability tooling, which stops at the JSON-RPC transport boundary.[0]
  • For MCP, the researcher argues exposure should be treated as equivalent to reachability: anything in the served tool manifest should be assumed reachable, with risk reduced only by controls outside the model such as allowlists, scopes, and human confirmation.[0]
  • A simple static-analysis rule over tool manifests and handlers surfaced a CVSS 8.0 SSRF in Google's own toolbox, underscoring how under-examined this category currently is.[0]

Defensive actions

  • Upgrade the Google MCP Toolbox for Databases to the release containing PR #3448: The patch adds an SSRF guard with DNS-rebinding/TOCTOU protection, IP-range allow/block lists, and fail-fast base-URL validation, remediating the redirect-based SSRF[0]
  • Treat MCP tool servers as a first-class dependency class and audit their served tool manifests and handlers directly: Standard software-composition-analysis reachability engines cannot see past the JSON-RPC transport boundary, so exposure in the served manifest should be assumed reachable and reviewed with dedicated tooling[0]