Path Traversal Vulnerability in Nikolaibibo's Image Upload Component
CVE-2026-19371
4.8MEDIUM
What is CVE-2026-19371?
A path traversal vulnerability exists in the image upload functionality of the claude-comfyui-mcp component, specifically within the copyFileSync function located in the src/tools/utils.ts file. This flaw allows an attacker to manipulate the image_path argument, potentially leading to unauthorized file system access. The vulnerability was disclosed to the project maintainers via an issue report, though no resolution has been provided to date. This emphasizes the need for immediate attention to mitigate potential exploitation risks.
Affected Version(s)
claude-comfyui-mcp 1.0.0
