What is CVE-2026-14540?
CVE-2026-14540 is a Server-Side Request Forgery (SSRF) vulnerability in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. Despite baseline input sanitization, the underlying HTTP client allows unauthorized requests to internal resources. Users should immediately update to the latest version and review network access controls.
Azərbaycanca: CVE-2026-14540 Google mcp-toolbox-in 0.3.0-dan 1.4.0-a qədər versiyalarında generic HTTP mənbəsi və alət komponentlərində Server-Side Request Forgery (SSRF) zəifliyidir. Baza giriş təmizlənməsinə baxmayaraq, HTTP müştərisi üzərindən daxili resurslara icazəsiz sorğular göndərməyə imkan verir. İstifadəçilər dərhal ən son versiyaya yeniləməli və şəbəkə giriş nəzarətlərini nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: Google
FAQ2
Which versions of Google mcp-toolbox are affected by CVE-2026-14540?
This SSRF vulnerability affects Google mcp-toolbox versions 0.3.0 through 1.4.0.
What measures should be taken to protect against CVE-2026-14540?
Users should immediately update to the latest version and review network access controls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.