Critical MCP Toolbox Vulnerability Exposes Enterprise Databases
ID: b69c0f57-8f17-5fcd-b331-0c1709c7630b
STIX ID: report--b69c0f57-8f17-5fcd-b331-0c1709c7630b
Feed Name: securityonline.info
Security researchers disclosed CVE-2026-9739 affecting the open-source MCP Toolbox: a hardcoded wildcard access-control header in the Server-Sent Events handler overrides CORS protections, allowing malicious websites to bypass security controls, hijack sessions, and proxy requests to exfiltrate data from linked databases (e.g., Postgres, BigQuery). Impact primarily affects deployments using the v2024-11-05 protocol; remediation is to remove the hardcoded header so global middleware correctly enforces origin restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
