Path Traversal Vulnerability in danielpopamd Linkedin Ads MCP Media Upload Component
CVE-2026-81485
Key Information:
- Vendor
Danielpopamd
- Status
- Vendor
- CVE Published:
- 27 August 2026
Badges
What is CVE-2026-81485?
A security vulnerability has been identified in the danielpopamd Linkedin Ads MCP version 1.0.0. This vulnerability arises from an unsafe implementation in the function fs.readFileSync located in the file src/tools/campaign-management.ts, which handles media uploads. An attacker can manipulate the filePath argument to exploit this path traversal issue, potentially allowing unauthorized access to sensitive files on the server. The vulnerability has been publicly disclosed and remains unaddressed despite prior notifications to the project through an issue report.
Affected Version(s)
linkedin-ads-mcp 1.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
