目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-15829— Google MCP Toolbox for Databases 授权问题漏洞

AI Predicted 8.6 Difficulty: Easy EPSS 0.18% · P7

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
GoogleMCP Toolbox for Databases (googleapis/mcp-toolbox)0.13.0≤ 1.3.0affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-15829の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
SQL Injection and Security Boundary Bypass in googleapis/mcp-toolbox
ソース: CVE Program / CVE List V5
脆弱性説明
A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and interpolates them unescaped via fmt.Sprintf directly into a generated AI.FORECAST table-valued SELECT statement. While MCP Toolbox utilizes an allowedDatasets mechanism to restrict queries, this defense only validates the history_data parameter; the final assembled query is executed without re-validation. An attacker can break out of the string literal fields (such as timestamp_col) to inject a valid multi-statement or cross-dataset query block. This allows an unauthorized user to bypass the operator-configured allowedDatasets boundary and read arbitrary BigQuery tables.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
ソース: CVE Program / CVE List V5
脆弱性タイトル
Google MCP Toolbox for Databases 授权问题漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Google MCP Toolbox for Databases是美国Google公司的数据库管理工具。 Google MCP Toolbox for Databases 0.13.0版本至1.3.0版本存在安全漏洞,该漏洞源于预置的BigQuery预测工具接受客户端控制的参数(data_col、timestamp_col和id_cols)作为纯字符串,并通过fmt.Sprintf未经转义地直接插值到生成的AI.FORECAST表值SELECT语句中,且allowedDatasets机制仅验证histor
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
GoogleMCP Toolbox for Databases (googleapis/mcp-toolbox) 0.13.0 ~ 1.3.0 -

II. CVE-2026-15829の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-15829のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-15829 补丁与修复 (1)

Same Patch Batch · Google · 2026-07-21 · 14 CVEs total

CVE-2026-16423Google Chrome 资源管理错误漏洞
CVE-2026-16424Google Chrome 资源管理错误漏洞
CVE-2026-16418Google Chrome 缓冲区错误漏洞
CVE-2026-16422Google Chrome 输入验证错误漏洞
CVE-2026-16419Google Chrome 安全漏洞
CVE-2026-16417Google Chrome 异常处理不当漏洞
CVE-2026-16415Google Chrome 输入验证错误漏洞
CVE-2026-16416Google Chrome 数字错误漏洞
CVE-2026-16414Google Chrome 输入验证错误漏洞
CVE-2026-16413Google Chrome 缓冲区错误漏洞
CVE-2026-16421Google Chrome 安全漏洞
CVE-2026-16420Google Chrome 缓冲区错误漏洞
CVE-2026-15432Observable Timing Discrepancy in Tink-Java and Tink-Android ChunkedMacVerification

IV. 関連脆弱性

V. CVE-2026-15829へのコメント

まだコメントはありません


コメントを残す