Path Traversal Vulnerability in Mindpilot-MCP by Abrinsmead
CVE-2026-19287
4.8MEDIUM
What is CVE-2026-19287?
A security flaw has been identified in version 0.5.0 of Mindpilot-MCP developed by Abrinsmead. This vulnerability arises from a manipulation of the argument ID within the HistoryService component, allowing potential attackers to exploit path traversal. This attack must be executed locally, highlighting a significant risk to systems utilizing this version of the product. Despite an early notification from the community regarding this issue, there has yet to be an official response or patch from the vendor.
Affected Version(s)
mindpilot-mcp 0.5.0
