Path Traversal Vulnerability in dekdee Adobe XD MCP Product
CVE-2026-79622
Key Information:
- Vendor
Dekdee
- Status
- Vendor
- CVE Published:
- 25 August 2026
Badges
What is CVE-2026-79622?
A path traversal vulnerability has been detected in the dekdee Adobe XD MCP product, specifically within the function of the file-access-from-request endpoint located in src/parsers/xd-parser.ts. This weakness allows attackers to manipulate the outputFile/outputDir arguments, potentially gaining unauthorized access to file system resources. The threat can be executed remotely, raising significant security concerns. Although the project team was notified about this issue early through an issue report, no official response or resolution has been provided to mitigate the risks associated with this vulnerability.
Affected Version(s)
adobe-xd-mcp 1.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
