I found an SSRF in Google's official AI tooling, and how Google reacted
Hacker News
Read full postA security researcher discovered a server-side request forgery (SSRF) vulnerability in Google's MCP Toolbox, which allows outbound requests to be manipulated via redirects. Google promptly fixed the issue within eight days, credited the researcher, and assigned CVE-2026-14540. The flaw was particularly risky due to the nature of agent tooling, where input URLs are often model-generated and untrusted.



