A vulnerability, which was classified as problematic, was found in Google MCP Toolbox for Databases up to 1.4.0. This impacts an unknown function. Such manipulation of the argument pageURL leads to server-side request forgery.
This vulnerability is documented as CVE-2026-16481. The attack can be executed remotely. There is not any exploit available.