Path Traversal Vulnerability in automateyournetwork MCPyATS
CVE-2026-19338
4.8MEDIUM
What is CVE-2026-19338?
A path traversal vulnerability exists in automateyournetwork MCPyATS versions up to 0.1.4, specifically in the processGenerateRequest function located in the mcp_servers/mermaid/index.ts file. This vulnerability allows an attacker to manipulate input parameters leading to unauthorized access to directory files. The attack must be executed locally, making it crucial for users to restrict access and validate inputs to mitigate potential risks.
Affected Version(s)
MCPyATS 0.1.0
MCPyATS 0.1.1
MCPyATS 0.1.2
