Path Traversal Vulnerability in Handwriting-OCR Handwriting-OCR-MCP-Server
CVE-2026-19372

4.8MEDIUM

Key Information:

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19372?

A security flaw exists in the Handwriting-OCR handwriting-ocr-mcp-server version 0.1.0, specifically in the upload_document function. This vulnerability arises from improper handling of user input in the fs.readFileSync method located in src/index.ts, allowing attackers to manipulate the File argument, potentially leading to unauthorized access to file system paths. Attackers must execute this locally. Despite being reported, there has been no response from the project team regarding a patch or fix.

Affected Version(s)

handwriting-ocr-mcp-server 0.1.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu05 (VulDB User)
VulDB CNA Team
.