Path Traversal Vulnerability in angrysky56 Advanced-Reasoning-MCP
CVE-2026-19330

4.8MEDIUM

Key Information:

Vendor

Angrysky56

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19330?

A path traversal vulnerability has been identified in the angrysky56 Advanced-Reasoning-MCP version 1.0.0, specifically within the function create_system_json/create_library in src/index.ts. This flaw allows attackers with local access to manipulate file paths, potentially leading to unauthorized file access. Despite being reported through appropriate channels, the vendor has yet to address the issue.

Affected Version(s)

advanced-reasoning-mcp 1.0.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu03 (VulDB User)
VulDB CNA Team
.