Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-86439

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Sep 07, 2026
Vendor unknown

Description

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server process.

References