CVE-2026-14540: an SSRF in Google's official MCP Toolbox for Databases, CVSS 8.0, credited by name in the fix. Why the bug class is invisible to standard dependency scanners.
1 comment
rfgplk3 days ago
Google's products are littered with CVEs. Disappointing for a supposed "frontier" lab. Can't they hire competent people?
Read the full thread on Hacker News →
Related stories
- Hacker News · 1 points · 4 days ago
- Hacker News · 1 points · 6 days ago
- Hacker News · 1 points · 6 days ago
- Launch HN: Vespper (YC F24) – SOTA Docx MCPvespper.comHacker News · 31 points · 2 days ago
- DEV Community · 10 points · 11 days ago
- Show HN: Vespper (YC F24) – Docx MCPvespper.comHacker News · 5 points · 2 days ago