Path Traversal Vulnerability in Mindpilot-MCP by Abrinsmead
CVE-2026-19287

4.8MEDIUM

Key Information:

Vendor

Abrinsmead

Vendor
CVE Published:
8 August 2026

What is CVE-2026-19287?

A security flaw has been identified in version 0.5.0 of Mindpilot-MCP developed by Abrinsmead. This vulnerability arises from a manipulation of the argument ID within the HistoryService component, allowing potential attackers to exploit path traversal. This attack must be executed locally, highlighting a significant risk to systems utilizing this version of the product. Despite an early notification from the community regarding this issue, there has yet to be an official response or patch from the vendor.

Affected Version(s)

mindpilot-mcp 0.5.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu02 (VulDB User)
VulDB CNA Team
.