Path Traversal Vulnerability in aktsmm skill-ninja-mcp-server
CVE-2026-19328

4.8MEDIUM

Key Information:

Vendor

Aktsmm

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19328?

A vulnerability exists in aktsmm skill-ninja-mcp-server version 0.1.0, specifically in the functions responsible for managing skills and agents. The issue arises from improper handling of the workspacePath argument, which can lead to local path traversal attacks. Attackers can potentially manipulate this parameter to access unauthorized files on the server. To protect your application, it is essential to upgrade to version 0.1.1, which includes a fix for this issue. Refer to the relevant patch for detailed improvements.

Affected Version(s)

skill-ninja-mcp-server 0.1.0

skill-ninja-mcp-server 0.1.1

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu03 (VulDB User)
.