Path Traversal Vulnerability in huangjunsen0406 xiaozhi-mcphub
CVE-2026-8116
Key Information:
- Vendor
Huangjunsen0406
- Status
- Vendor
- CVE Published:
- 7 May 2026
Badges
What is CVE-2026-8116?
A vulnerability has been discovered in the huangjunsen0406 xiaozhi-mcphub project, specifically impacting the file src/controllers/dxtController.ts. This weakness allows an attacker to manipulate the argument manifest.name, leading to path traversal incidents. The exploit, which poses a significant threat due to its public availability, can be initiated remotely, potentially allowing unauthorized access to sensitive files within the application. Despite early notification of the issue via an issue report to the project maintainers, no response has been forthcoming.
Affected Version(s)
xiaozhi-mcphub 1.0.0
xiaozhi-mcphub 1.0.1
xiaozhi-mcphub 1.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
