Path Traversal Vulnerability in BlenderMCP Affects File Security
CVE-2026-66004
Key Information:
- Vendor
Ahujasid
- Status
- Vendor
- CVE Published:
- 24 July 2026
Badges
What is CVE-2026-66004?
BlenderMCP prior to commit 30a3308 features a path traversal vulnerability within the download_polyhaven_asset method. This flaw enables attackers to write arbitrary files by injecting harmful traversal sequences into API response keys. If an attacker successfully executes a MITM (Man-In-The-Middle) attack or conducts prompt injections, they can manipulate file paths, such as '../../../../.bashrc', allowing them to overwrite sensitive files. This could lead to persistent code execution, ultimately undermining the integrity and security of the affected systems.
Affected Version(s)
blender-mcp 0 < 30a3308446cd8f81a9446e5a2ed657c0d8d86072
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
