CVE-2026-15829 | Google MCP Toolbox for Databases up to 1.3.0 Forecast fmt.Sprintf data_col/timestamp_col/id_cols sql injection
A vulnerability labeled as critical has been found in Google MCP Toolbox for Databases up to 1.3.0. This issue affects the function fmt.Sprintf of the component Forecast. Such manipulation of the argument data_col/timestamp_col/id_cols leads to sql injection.
This vulnerability is listed as CVE-2026-15829. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More