Path Traversal Vulnerability in new-mcp by bartekke8it56w2
CVE-2026-19370

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 August 2026

What is CVE-2026-19370?

A vulnerability exists in the new-mcp 0.1.0 package developed by bartekke8it56w2, specifically affecting the functions fs.writeFileSync, fs.existsSync, and fs.readFileSync within the index.ts file of the geminithinking component. An attacker with local access can manipulate the input arguments sessionCommand and sessionPath, leading to unauthorized file access through a path traversal attack. Despite early notification from the community regarding this issue, no mitigation has been reported from the project maintainers thus far.

Affected Version(s)

new-mcp 0.1.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu05 (VulDB User)
VulDB CNA Team
.