Path Traversal Vulnerability in arben-adm mcp-sequential-thinking
CVE-2026-81845
Key Information:
- Vendor
Arben-adm
- Status
- Vendor
- CVE Published:
- 27 August 2026
Badges
What is CVE-2026-81845?
A path traversal vulnerability exists in the mcp-sequential-thinking component's import_session/export_session functionality. This issue is due to improper validation of the 'file_path' argument in server.py, allowing attackers to access unintended files on the server. This vulnerability can be exploited remotely, making it critical for affected users to upgrade to version 0.6.0 or later. A detailed patch has been released, addressing the identified issue.
Affected Version(s)
mcp-sequential-thinking 0.1
mcp-sequential-thinking 0.2
mcp-sequential-thinking 0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
