Hulupeep · Mcp-Ui-Probe · CVE-2026-19270
**Name of the Vulnerable Software and Affected Versions**
Hulupeep mcp-ui-probe versions prior to 0.2.1
**Description**
A path traversal flaw exists in the Journey/Usage component within the `src/journey/JourneyStorage.ts` file. This issue occurs when the `journeyId` or `filename` arguments are manipulated in the `get journey()`, `delete journey()`, `analyze journey()`, and `usage stats()` functions. Path traversal is a vulnerability that allows an attacker to access files and directories that are stored outside the web root folder. Exploitation of this flaw requires a local approach.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `get journey()`, `delete journey()`, `analyze journey()`, and `usage stats()` functions to minimize the risk of exploitation.