—
GO-2026-6411
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox
Quick fix
GO-2026-6411 — github.com/googleapis/mcp-toolbox: upgrade to the fixed version with the command below.
go get github.com/googleapis/mcp-toolbox@v1.3.0Details
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/googleapis/mcp-toolbox
Introduced in:
0Fixed in: 1.3.0Fix
go get github.com/googleapis/mcp-toolbox@v1.3.0References
- https://github.com/advisories/GHSA-vwxw-jrg6-9jxv[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-11720[ADVISORY]
- https://github.com/googleapis/mcp-toolbox/commit/80a66021205e032a424fff87b3dc6d92da58aa77[FIX]
- https://github.com/googleapis/mcp-toolbox/pull/3218[FIX]
- https://github.com/googleapis/mcp-toolbox/releases/tag/v1.3.0[WEB]