Path Traversal Vulnerability in Hulupeep mcp-ui-probe Product
CVE-2026-19270
4.8MEDIUM
What is CVE-2026-19270?
A security flaw has been identified in Hulupeep's mcp-ui-probe up to version 0.2.0. This vulnerability resides in the functions related to journey management, specifically get_journey, delete_journey, analyze_journey, and usage_stats, located in the src/journey/JourneyStorage.ts file. The flaw allows attackers to exploit improper handling of the journeyId or filename parameters, leading to unauthorized access to the file system via path traversal. Notably, this attack requires a local approach, and despite early notification of the issue through an issue report, the project team has yet to address the vulnerability.
Affected Version(s)
mcp-ui-probe 0.1
mcp-ui-probe 0.2.0
