PT-2026-45498 · J3K0 · Mcp-Google-Workspace

·

CVE-2026-10277

·

Published

2026-06-01

·

Updated

2026-06-01

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions j3k0 mcp-google-workspace versions prior to 89c091ecf8b9f9c7291d1af0b1966e271f86551c
Description Improper access controls exist within the MCP Gmail Tool component. A remote attacker can exploit this issue by manipulating the saveToDisk() function located in the src/tools/gmail.ts file.
Recommendations Install patch 89c091ecf8b9f9c7291d1af0b1966e271f86551c. As a temporary workaround, restrict the use of the saveToDisk() function until the patch is applied.

Exploit

Fix

Incorrect Privilege Assignment

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10277

Affected Products

Mcp-Google-Workspace