Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-19202: mcp-toolbox-sdk-python reuses Google token across services

CVE-2026-19202 · published 6 days ago
Summary

The mcp-toolbox-sdk-python library stores a Google login token in a shared cache without distinguishing which service it is for. If your app talks to more than one Google service at the same time, the token meant for a sensitive service could be sent to a different service, allowing someone who sees that traffic to pretend to be your app when talking to the original service. Update to a version that separates cached tokens by service or disable the shared cache until a fix is applied.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
google mcp-toolbox-sdk-python <= 1.1.0
Original advisory text
Token Cache Reuse in mcp-toolbox-sdk-python
A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. If an application uses the SDK to authenticate to two or more different audiences within the same process, the module-level token cache fails to key its cached tokens by the requested audience. Consequently, a valid, unexpired token minted for a sensitive service (Service A) can be retrieved from the cache and sent to a secondary service (Service B). An attacker who operates, compromises, or monitors traffic to Service B can capture this token and replay it to impersonate the victim application against Service A.
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-524Use of Cache Containing Sensitive Information
Timeline
Published22 Sep 2026
Updated27 Sep 2026
First seen22 Sep 2026
Sources
CVE-2026-19202 · MITRE
Track software like this
Free during beta