FAIL › dossier
mcp toolbox for databases
PRODUCTDossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-06-29 | CVE-2026-11720 | critical | A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While |
| 2026-07-31 | CVE-2026-14537 | critical | CVE-2026-14537: Incorrect Authorization in the direct HTTP API tool invocation endpoint in Googl |
| 2026-06-18 | CVE-2026-11718 | critical | CVE-2026-11718: An authentication bypass vulnerability exists in the generic opaque token valida |
| 2026-06-18 | CVE-2026-11717 | critical | CVE-2026-11717: An authentication bypass vulnerability exists in the generic opaque token valida |