Skip to content

CVE lookup

CVE-2026-14537

Pruva has a verified reproduction for CVE-2026-14537: mcp-toolbox authorization bypass: unauthenticated tool invocation via direct HTTP API. The canonical evidence record is REPRO-2026-00318.

REPRO

REPRO-2026-00318

Package

googleapis/genai-toolbox · github

Severity

HIGH

Status

published