processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path traversal.This vulnerability is listed as CVE-2026-19338. The attack must be carried out locally. In addition, an exploit is available.
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf vuldb.com.
SOCIAL SHARE CARD GENERATOR