Path Traversal Vulnerability in Ichigo3766 Image Generation Component
CVE-2026-19365

4.8MEDIUM

Key Information:

Vendor

Ichigo3766

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19365?

A path traversal vulnerability exists in Ichigo3766's image-gen-mcp version 0.1.0, where improper handling of the output_path argument in src/index.ts allows an attacker to traverse directories. This exposure can lead to unauthorized access to the file system, as the attack must be executed locally, bypassing intended restrictions. The issue was reported to the developers; however, no response has been documented, raising concerns for users relying on this component.

Affected Version(s)

image-gen-mcp 0.1.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu05 (VulDB User)
VulDB CNA Team
.