Path Traversal Vulnerability in debugmcp mcp-debugger by Debugmcp
CVE-2026-9467
Key Information:
- Vendor
Debugmcp
- Status
- Vendor
- CVE Published:
- 25 May 2026
Badges
What is CVE-2026-9467?
A vulnerability exists in the debugmcp mcp-debugger up to version 0.20.0, specifically within the handleGetSourceContext function located in the src/server.ts file. This flaw allows an attacker to perform path traversal attacks remotely, potentially exposing sensitive file paths and contents. As the exploit is publicly available, it raises significant concerns for users of the affected product. The vendor has been notified about this issue but has not provided a response.
Affected Version(s)
mcp-debugger 0.1
mcp-debugger 0.2
mcp-debugger 0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
