Path Traversal Vulnerability in Nikolaibibo's Image Upload Component
CVE-2026-19371

4.8MEDIUM

Key Information:

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19371?

A path traversal vulnerability exists in the image upload functionality of the claude-comfyui-mcp component, specifically within the copyFileSync function located in the src/tools/utils.ts file. This flaw allows an attacker to manipulate the image_path argument, potentially leading to unauthorized file system access. The vulnerability was disclosed to the project maintainers via an issue report, though no resolution has been provided to date. This emphasizes the need for immediate attention to mitigate potential exploitation risks.

Affected Version(s)

claude-comfyui-mcp 1.0.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu05 (VulDB User)
VulDB CNA Team
.