Description
A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of the component MCP Gmail Tool. Performing a manipulation results in improper access controls. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The patch is named 89c091ecf8b9f9c7291d1af0b1966e271f86551c. It is suggested to install a patch to address this issue.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2026-05-31: | Advisory disclosed |
| 2026-05-31: | VulDB entry created |
| 2026-05-31: | VulDB entry last update |
Credits
ccccccctfi (VulDB User)
References
vuldb.com/vuln/367570 (VDB-367570 | j3k0 mcp-google-workspace MCP Gmail Tool gmail.ts saveToDisk access control)
vuldb.com/vuln/367570/cti (VDB-367570 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10277 (CVE-2026-10277 | CVE Analysis and Report)
vuldb.com/submit/825416 (Submit #825416 | j3k0 mcp-google-workspace 1.0.0 Arbitrary File Write)
github.com/j3k0/mcp-google-workspace/issues/19
github.com/j3k0/mcp-google-workspace/pull/22
github.com/...ommit/89c091ecf8b9f9c7291d1af0b1966e271f86551c
github.com/j3k0/mcp-google-workspace/