CVE-2026-14540: an SSRF in Google's official MCP Toolbox for Databases, CVSS 8.0, credited by name in the fix. Why the bug class is invisible to standard dependency scanners.

1 points•AnasSyed28•3 days ago•1 comment•

1 comment

rfgplk3 days ago
Google's products are littered with CVEs. Disappointing for a supposed "frontier" lab. Can't they hire competent people?

Read the full thread on Hacker News →

Related stories