Path Traversal Vulnerability in Handwriting-OCR Handwriting-OCR-MCP-Server
CVE-2026-19372
4.8MEDIUM
What is CVE-2026-19372?
A security flaw exists in the Handwriting-OCR handwriting-ocr-mcp-server version 0.1.0, specifically in the upload_document function. This vulnerability arises from improper handling of user input in the fs.readFileSync method located in src/index.ts, allowing attackers to manipulate the File argument, potentially leading to unauthorized access to file system paths. Attackers must execute this locally. Despite being reported, there has been no response from the project team regarding a patch or fix.
Affected Version(s)
handwriting-ocr-mcp-server 0.1.0
