CVE-2026-14537

Summary

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the –enable-api flag is active.

Affected Software

VendorProductVersion RangeStatus
Googlemcp-toolbox1.3.0affected
Googlemcp-toolboxv1.4.0affected

Weaknesses

  • CWE-863: CWE-863 (Incorrect Authorization)

References