THREAT OPS › Threat News › [NVD] CVE-2026-15829 (HIGH 8.1) — A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox.
The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and
[NVD] CVE-2026-15829 (HIGH 8.1) — A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and
CVE-2026-15829 CVSS: 8.1 HIGH Published: 2026-07-21T17:17:05.350
A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox.
The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and interpolates them unescaped via fmt.Sprintf directly
Indicators of compromise
- CVE-2026-15829cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-15829