Known Vulnerabilities for Toolbox by Jetbrains
Listed below are 6 of the newest known vulnerabilities associated with "Toolbox" by "Jetbrains".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-102242 json | Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versi... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-69089 json | Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argu... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-56744 json | `@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/w... | Not Provided | 2026-09-24 | 2026-09-28 |
| CVE-2026-31230 json | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow... | Not Provided | 2026-05-12 | 2026-08-11 |
| CVE-2026-31228 json | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component... | Not Provided | 2026-05-12 | 2026-08-12 |
| CVE-2026-19202 json | A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and... | Not Provided | 2026-09-22 | 2026-09-23 |
| CVE-2026-16481 json | A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page... | Not Provided | 2026-07-27 | 2026-09-10 |
| CVE-2026-15829 json | A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting too... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-14541 json | An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-too... | Not Provided | 2026-07-31 | 2026-07-31 |
| CVE-2026-14540 json | A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbo... | Not Provided | 2026-07-31 | 2026-07-31 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jetbrains | Toolbox | 2019.2 | |||
| Application | Jetbrains | Toolbox | 2019.1 | |||
| Application | Jetbrains | Toolbox | 2017.3 | |||
| Application | Jetbrains | Toolbox | 2017.2 | |||
| Application | Jetbrains | Toolbox | 2017.1 | |||
| Application | Jetbrains | Toolbox | 2016.1 | |||
| Application | Jetbrains | Toolbox | 1.5 | |||
| Application | Jetbrains | Toolbox | 1.3 | |||
| Application | Jetbrains | Toolbox | 1.18 | |||
| Application | Jetbrains | Toolbox | 1.17.6856 | |||
| Application | Jetbrains | Toolbox | 1.17.6802 | |||
| Application | Jetbrains | Toolbox | 1.17 | |||
| Application | Jetbrains | Toolbox | 1.15.5666 | |||
| Application | Jetbrains | Toolbox | 1.15.5605 | |||
| Application | Jetbrains | Toolbox | 1.15 | |||
| Application | Jetbrains | Toolbox | 1.14 | |||
| Application | Jetbrains | Toolbox | 1.13 | |||
| Application | Jetbrains | Toolbox | 1.11 | |||
| Application | Jetbrains | Toolbox | 1.0 | |||
| Application | Jetbrains | Toolbox | 1.0 |