Path Traversal Vulnerability in automateyournetwork MCPyATS
CVE-2026-19338

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 August 2026

What is CVE-2026-19338?

A path traversal vulnerability exists in automateyournetwork MCPyATS versions up to 0.1.4, specifically in the processGenerateRequest function located in the mcp_servers/mermaid/index.ts file. This vulnerability allows an attacker to manipulate input parameters leading to unauthorized access to directory files. The attack must be executed locally, making it crucial for users to restrict access and validate inputs to mitigate potential risks.

Affected Version(s)

MCPyATS 0.1.0

MCPyATS 0.1.1

MCPyATS 0.1.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu04 (VulDB User)
.