Path Traversal Vulnerability in Pimzino Spec-Workflow-MCP by Pimzino
CVE-2026-19336

4.8MEDIUM

Key Information:

Vendor

Pimzino

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19336?

A path traversal vulnerability has been identified in the ApprovalStorage.createApproval function within the Pimzino spec-workflow-mcp product versions up to 2.2.6. This flaw allows an attacker with local access to manipulate the categoryName argument, potentially gaining unauthorized access to sensitive files on the system. To mitigate this risk, it is strongly recommended that users upgrade to version 2.2.7, which includes a patch specifically addressing this issue. For more details on the vulnerability, you can refer to the official patch documentation.

Affected Version(s)

spec-workflow-mcp 2.2.0

spec-workflow-mcp 2.2.1

spec-workflow-mcp 2.2.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu04 (VulDB User)
.