Path Traversal Vulnerability in MonomythDevelopment Screenshot Element Tool
CVE-2026-19038

5.3MEDIUM

Key Information:

Vendor
CVE Published:
6 August 2026

What is CVE-2026-19038?

A security vulnerability has been identified in the MonomythDevelopment screenshot_element Tool, where the function screenshotElement can be exploited remotely due to improper handling of the output_name argument. This flaw enables attackers to traverse file paths, potentially leading to unauthorized access to sensitive files on the server. Users are strongly recommended to upgrade to version 1.1.1, which resolves the issue following a timely response and professional action by the vendor.

Affected Version(s)

la-forge-mcp 1.0.0

la-forge-mcp 1.1.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu (VulDB User)
VulDB CNA Team
.