Path Traversal Vulnerability in HelloGGX shadcn-vue-mcp Product
CVE-2026-19324
4.8MEDIUM
What is CVE-2026-19324?
A vulnerability has been found in HelloGGX shadcn-vue-mcp affecting the fs.promises.readFile function within the src/server/callback-server.ts file. This issue allows for potential path traversal manipulation through user-controlled arguments. The attack is limited to local execution, making it crucial for developers to address this weakness, especially since the product operates on a rolling release strategy and does not specify version details for affected releases. The HelloGGX team was notified about this issue through an early report but has yet to respond.
Affected Version(s)
shadcn-vue-mcp e170e277b94235cde627803277fc8c41103a4d38
