Beveiligingsadvies

CVE-2026-19370

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-09 22:00:10
Laatst bijgewerkt 2026-08-10 17:30:16
Toegewezen door VulDB
CVSS-score 5.3
Status PUBLISHED

Beschrijving

A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the argument sessionCommand/sessionPath causes path traversal. The attack requires local access. The project was informed of the problem early through an issue report but has not responded yet.