Path Traversal Vulnerability in HelloGGX shadcn-vue-mcp Product
CVE-2026-19324

4.8MEDIUM

Key Information:

Vendor

Helloggx

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19324?

A vulnerability has been found in HelloGGX shadcn-vue-mcp affecting the fs.promises.readFile function within the src/server/callback-server.ts file. This issue allows for potential path traversal manipulation through user-controlled arguments. The attack is limited to local execution, making it crucial for developers to address this weakness, especially since the product operates on a rolling release strategy and does not specify version details for affected releases. The HelloGGX team was notified about this issue through an early report but has yet to respond.

Affected Version(s)

shadcn-vue-mcp e170e277b94235cde627803277fc8c41103a4d38

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu03 (VulDB User)
VulDB CNA Team
.