Beveiligingsadvies

CVE-2026-19279

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-08 10:15:09
Laatst bijgewerkt 2026-08-10 14:38:38
Toegewezen door VulDB
CVSS-score 5.3
Status PUBLISHED

Beschrijving

A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the file src/index.ts. Such manipulation of the argument pdfPath/sessionId leads to command injection. The attack can only be performed from a local environment. The project was informed of the problem early through an issue report but has not responded yet.