Executive brief
Google's MCP Toolbox, a tool used for connecting databases to AI models, contains a security flaw in how it verifies user identity. An attacker can bypass authentication by providing a specially crafted security token that omits a required status field, tricking the system into granting unauthorized access. This could allow an attacker to access protected tools and sensitive underlying data sources without valid credentials.
Technical details
An authentication bypass exists in the `validateOpaqueToken` function of the MCP Toolbox. When performing OAuth 2.0 introspection (RFC 7662), the toolbox decodes the response into a struct where the `Active` field is a boolean pointer (`*bool`). The validation logic only rejects tokens if the field is explicitly present and set to `false`. If an introspection endpoint returns a payload that entirely omits the mandatory `active` key, the pointer remains `nil`, causing the validation check to short-circuit and incorrectly treat the token as valid. This allows remote, unauthenticated attackers to bypass security controls and access protected resources. The issue is addressed in pull request #3341.
Affected products
- Google MCP Toolbox for Databases (mcp-toolbox) 1.0.0 to 1.3.0
Timeline
- 2026-06-03: patched: Fix submitted via Pull Request 3341
- 2026-06-18: disclosed: CVE published to NVD