PT-2026-45498 · J3K0 · Mcp-Google-Workspace
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
j3k0 mcp-google-workspace versions prior to 89c091ecf8b9f9c7291d1af0b1966e271f86551c
Description
Improper access controls exist within the MCP Gmail Tool component. A remote attacker can exploit this issue by manipulating the
saveToDisk() function located in the src/tools/gmail.ts file.Recommendations
Install patch 89c091ecf8b9f9c7291d1af0b1966e271f86551c.
As a temporary workaround, restrict the use of the
saveToDisk() function until the patch is applied.Exploit
Fix
Incorrect Privilege Assignment
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcp-Google-Workspace