CVE-2026-10277 Details
Description
A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of the component MCP Gmail Tool. Performing a manipulation results in improper access controls. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The patch is named 89c091ecf8b9f9c7291d1af0b1966e271f86551c. It is suggested to install a patch to address this issue.
A vulnerability exists in j3k0 mcp-google-workspace versions through 831790e7d5c2663325733d9f5579cc339a267c4c. The issue is in the Gmail tool's attachment saving function, which fails to properly validate user-supplied file paths. This flaw allows an attacker to write attachment content to arbitrary locations on the server where the process has write permissions. The vulnerability can be exploited remotely, and the published exploit takes advantage of this flaw by sending a crafted request that includes a path to a file on the victim's system.
Users are advised to update to the patched version of j3k0 mcp-google-workspace, which is available on the project's GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 1, 2026CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/j3k0/mcp-google-workspace/ | [email protected] | Source CodeVendor |
| https://github.com/j3k0/mcp-google-workspace/commit/89c091ecf8b9f9c7291d1af0b1966e271f86551c | [email protected] | Source CodeVendor |
| https://github.com/j3k0/mcp-google-workspace/issues/19 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/j3k0/mcp-google-workspace/pull/22 | [email protected] | Source CodeVendor |
| https://vuldb.com/cve/CVE-2026-10277 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/825416 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/367570 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/367570/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| j3k0 mcp-google-workspace | <= 831790e7d5c2663325733d9f5579cc339a267c4c |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | New CVE Received | [email protected] |
Volerion