Junglewise Threat Intelligence

CVE-2026-10277: j3k0 mcp-google-workspace arbitrary file write in Gmail Tool

CVE-2026-10277 · Severity: medium · CVSS 6.3 · Published 2026-06-01

Executive brief

A vulnerability exists in the j3k0 mcp-google-workspace tool, which allows applications to interact with Google Workspace services. The software fails to properly restrict where it saves Gmail attachments on the host computer. An attacker could exploit this to write files to sensitive locations on the server, potentially leading to system disruption or unauthorized file modification.

Technical details

An arbitrary file write vulnerability (CWE-73/CWE-284) exists in the `saveToDisk` function within `src/tools/gmail.ts`. The application fails to validate user-supplied file paths against a safe base directory, instead passing them directly to `fs.writeFileSync` after an insufficient validation check. A remote attacker with the ability to invoke the MCP tool (potentially via prompt injection if the tool is used by an AI assistant) can provide absolute paths or traversal sequences to write attacker-controlled content to any location writable by the server process. The issue was addressed in commit 89c091e by introducing a sandboxed attachment directory and stricter path resolution logic.

Affected products

  • j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c

Timeline

  • 2026-04-20: disclosed: Vulnerability reported by researcher
  • 2026-05-13: patched: Fix merged in commit 89c091e
  • 2026-06-01: advisory: CVE-2026-10277 published

References