Skip to content
COOEY

FAIL › dossier

mcp toolbox for databases

PRODUCT

Dossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2026-06-29 CVE-2026-11720 critical A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While
2026-07-31 CVE-2026-14537 critical CVE-2026-14537: Incorrect Authorization in the direct HTTP API tool invocation endpoint in Googl
2026-06-18 CVE-2026-11718 critical CVE-2026-11718: An authentication bypass vulnerability exists in the generic opaque token valida
2026-06-18 CVE-2026-11717 critical CVE-2026-11717: An authentication bypass vulnerability exists in the generic opaque token valida