Path Traversal Vulnerability in MonomythDevelopment Screenshot Element Tool
CVE-2026-19038
5.3MEDIUM
What is CVE-2026-19038?
A security vulnerability has been identified in the MonomythDevelopment screenshot_element Tool, where the function screenshotElement can be exploited remotely due to improper handling of the output_name argument. This flaw enables attackers to traverse file paths, potentially leading to unauthorized access to sensitive files on the server. Users are strongly recommended to upgrade to version 1.1.1, which resolves the issue following a timely response and professional action by the vendor.
Affected Version(s)
la-forge-mcp 1.0.0
la-forge-mcp 1.1.1
