Npm · Advanced-Reasoning-Mcp · CVE-2026-19330
**Name of the Vulnerable Software and Affected Versions**
angrysky56 advanced-reasoning-mcp version 1.0.0
**Description**
A path traversal issue exists in the file `src/index.ts` within the functions `create system json()`, `create library()`, `get system json()`, and `switch memory library()`. Path traversal is a flaw that allows an attacker to access files and directories that are stored outside the intended folder. Exploiting this issue requires local access.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict the use of the functions `create system json()`, `create library()`, `get system json()`, and `switch memory library()` to minimize the risk of exploitation.