Path Traversal Vulnerability in NocteDefensor LudusMCP Software
CVE-2026-19366

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 August 2026

What is CVE-2026-19366?

A vulnerability has been identified in NocteDefensor LudusMCP up to version 1.0.24, specifically within the 'insert_creds_range_config' component. The issue resides in the manipulation of the 'configPath/outputPath' argument within the file 'src/tools/insertCredsRangeConfig.ts'. This flaw can potentially allow for a path traversal attack, meaning an attacker with local execution capabilities could exploit the vulnerability to access unauthorized file paths or data on the system. Attempts to notify the project maintainers have been made, but no response has yet been issued.

Affected Version(s)

LudusMCP 1.0.0

LudusMCP 1.0.1

LudusMCP 1.0.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu05 (VulDB User)
VulDB CNA Team
.