---
id: CVE-2026-15528
title: A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1
summary: >-
  A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue
  affects some unknown processing of the file kicad_mcp/utils/path_validator.py.
  Performing a manipulation of the argument project_path/schematic_path results
  in pr…
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-693
published: '2026-07-13'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15528'
references:
  - url: 'https://github.com/lamaalrajih/kicad-mcp/'
    label: cna@vuldb.com
  - url: 'https://github.com/lamaalrajih/kicad-mcp/issues/57'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-15528'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/854531'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377866'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377866/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-07-13T04:24:09.652Z'
epss: 0.00161
epssPercentile: 0.05667
---

## Overview

A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file kicad_mcp/utils/path_validator.py. Performing a manipulation of the argument project_path/schematic_path results in protection mechanism failure. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
