VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-19366Medium· 5.3
1mo ago

A flaw has been found in NocteDefensor LudusMCP up to 1.0.24

A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the component insert_creds_range_config. Executing a manipulation of the argument configPath…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19365Medium· 5.3
1mo ago

A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0

A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipulation of the argument output_path leads to path traversal…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19338Medium· 5.3
1mo ago

A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4

A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19336Medium· 5.3
1mo ago

A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6

A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19335Medium· 5.3
1mo ago

A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0

A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of the argument skillName leads to path tr…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19331Medium· 5.3
1mo ago

A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0

A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such manipulation leads to path traversal. An attack has to be approache…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19330Medium· 5.3
1mo ago

A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0

A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to get_system_json/switch_memory_library of the file src/index.ts. This manipulation causes…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19328Medium· 5.3
1mo ago

A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0

A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath le…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19327Medium· 5.3
1mo ago

A flaw has been found in abracadabra50 claude-sesh 1.0.0

A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enricher.ts. Executing a manipulation of the argument sessionId can lead to path traversal. …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19326Medium· 4.4
1mo ago

A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1

A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the file ai-doctor-server/src/filemanagement/filemanagement.service.ts. Performing a manipulation of the argument imagePa…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19325Medium· 5.3
1mo ago

A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e

A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19324Low· 3.3
1mo ago

A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38

A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-server.ts. This manipulation of the arg…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-19323Medium· 5.3
1mo ago

A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0

A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of the component analyze-projec. T…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19288Medium· 5.3
1mo ago

A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e

A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFile.ts of the component importRiveFile F…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19287Medium· 5.3
1mo ago

A flaw has been found in abrinsmead mindpilot-mcp 0.5.0

A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This manipulation of the argument ID causes path traversal. The attack needs to be launched lo…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19285Medium· 5.3
1mo ago

A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c

A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function JsonMemoryStorage.createDomain/JsonMemoryStorage.getMemories/JsonMemoryStorage.saveMemori…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19270Medium· 5.3
1mo ago

A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0

A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey/analyze_journey/usage_stats of the file src/journey/JourneyStorage.ts of the component Journey/Usage. The manip…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-47243Critical· 9.2PoC
1mo ago

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-fs path is vulnerable to a guest-root t…

▾ Abyssalkata-containers · kata-containersEPSS 0.20%via NVD
CVE-2026-47661None
1mo ago

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's `/$result` endpoint allows a caller who can obtain any valid async ex…

▾ SunlitEPSS 0.62%via NVD
CVE-2026-47659None
1mo ago

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's `/$result` endpoint allows a caller who can obtain any valid async ex…

▾ SunlitEPSS 0.62%via NVD
CVE-2026-19264Critical· 9.8PoC
1mo ago

Postiz is an open-source social media scheduling tool

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that direct…

▾ AbyssalEPSS 1.0%via NVD
CVE-2026-50540Critical· 9.6
1mo ago

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalida…

▾ MidnightEPSS 0.61%via NVD
CVE-2026-71557Medium· 6.3PoC
1mo ago

go-git is an extensible git implementation library written in pure Go

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciou…

▾ Twilightgo-git · github.com/go-git/go-git/v5EPSS 0.41%via NVD
GHSA-hmq2-w58f-27jcHigh· 8.2
1mo ago

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-62992Medium
1mo ago

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating…

▾ Sunlitsmarty · smarty/smartyEPSS 0.53%via NVD
CVE-2026-62996Medium
1mo ago

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers an…

▾ Sunlitsmarty · smarty/smartyEPSS 0.51%via NVD
CVE-2026-53976Critical· 9.1PoC
1mo ago

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorksp…

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorksp…

▾ AbyssalEPSS 2.6%via NVD
CVE-2026-64653None
1mo ago

GitHub CLI (gh) is GitHub’s official command line tool

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or resource…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-49163High· 8.8
1mo ago

Application Insights Profiler Elevation of Privilege Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Application Insights ProfilerEPSS 1.0%via CVEORG
CVE-2026-18427High· 7.5
1mo ago

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dot…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.66%via NVD
CWE-22 vulnerabilities (CVEs) — page 20 · VulnSea