Path Traversal Vulnerability in new-mcp by bartekke8it56w2
CVE-2026-19370
4.8MEDIUM
What is CVE-2026-19370?
A vulnerability exists in the new-mcp 0.1.0 package developed by bartekke8it56w2, specifically affecting the functions fs.writeFileSync, fs.existsSync, and fs.readFileSync within the index.ts file of the geminithinking component. An attacker with local access can manipulate the input arguments sessionCommand and sessionPath, leading to unauthorized file access through a path traversal attack. Despite early notification from the community regarding this issue, no mitigation has been reported from the project maintainers thus far.
Affected Version(s)
new-mcp 0.1.0
