Path Traversal Vulnerability in Ichigo3766 Image Generation Component
CVE-2026-19365
4.8MEDIUM
What is CVE-2026-19365?
A path traversal vulnerability exists in Ichigo3766's image-gen-mcp version 0.1.0, where improper handling of the output_path argument in src/index.ts allows an attacker to traverse directories. This exposure can lead to unauthorized access to the file system, as the attack must be executed locally, bypassing intended restrictions. The issue was reported to the developers; however, no response has been documented, raising concerns for users relying on this component.
Affected Version(s)
image-gen-mcp 0.1.0
