Path Traversal Vulnerability Found in PV-Bhat Gemsuite-mcp by PV-Bhat
CVE-2026-19368
4.8MEDIUM
What is CVE-2026-19368?
A path traversal vulnerability exists within the PV-Bhat gemsuite-mcp version 1.0.0, specifically related to the file handling functionality located in src/handlers/unified-gemini.ts. This issue allows an attacker to manipulate file_path/file_paths arguments, potentially leading to unauthorized file access on the server. This attack must originate from a local environment. Although the project was alerted about this vulnerability via an issue report, no official response has been documented to date.
Affected Version(s)
gemsuite-mcp 1.0.0
