Path Traversal Vulnerability in aktsmm skill-ninja-mcp-server
CVE-2026-19328
4.8MEDIUM
What is CVE-2026-19328?
A vulnerability exists in aktsmm skill-ninja-mcp-server version 0.1.0, specifically in the functions responsible for managing skills and agents. The issue arises from improper handling of the workspacePath argument, which can lead to local path traversal attacks. Attackers can potentially manipulate this parameter to access unauthorized files on the server. To protect your application, it is essential to upgrade to version 0.1.1, which includes a fix for this issue. Refer to the relevant patch for detailed improvements.
Affected Version(s)
skill-ninja-mcp-server 0.1.0
skill-ninja-mcp-server 0.1.1
