Path Traversal Vulnerability in Jane-xiaoer Skill-Vision-Control Product
CVE-2026-19335

4.8MEDIUM

Key Information:

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19335?

A vulnerability has been identified in the Jane-xiaoer skill-vision-control product affecting version 1.3.0. This issue pertains to the function getSkillVersionsDir in the src/svc/utils/config.ts file, where improper handling of the skillName argument allows for path traversal. The exploitation of this vulnerability can only occur within a local environment. Despite early notification of the issue through an issue report, the vendor has yet to respond or provide a resolution.

Affected Version(s)

skill-vision-control 1.0

skill-vision-control 1.1

skill-vision-control 1.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu04 (VulDB User)
VulDB CNA Team
.