Path Traversal Vulnerability in Pimzino Spec-Workflow-MCP by Pimzino
CVE-2026-19336
4.8MEDIUM
What is CVE-2026-19336?
A path traversal vulnerability has been identified in the ApprovalStorage.createApproval function within the Pimzino spec-workflow-mcp product versions up to 2.2.6. This flaw allows an attacker with local access to manipulate the categoryName argument, potentially gaining unauthorized access to sensitive files on the system. To mitigate this risk, it is strongly recommended that users upgrade to version 2.2.7, which includes a patch specifically addressing this issue. For more details on the vulnerability, you can refer to the official patch documentation.
Affected Version(s)
spec-workflow-mcp 2.2.0
spec-workflow-mcp 2.2.1
spec-workflow-mcp 2.2.2
