PT-2026-69251 · Unknown · Skill-Ninja-Mcp-Server

·

CVE-2026-19328

·

Published

2026-08-09

·

Updated

2026-08-12

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions aktsmm skill-ninja-mcp-server version 0.1.0
Description Local manipulation of the workspacePath argument in the getInstalledSkills(), installSkill(), updateAgentsMd(), and uninstallSkill() functions within the src/installer.ts file allows for path traversal. Path traversal is a condition where an attacker can access files or directories outside the intended folder by using special characters in a file path.
Recommendations Update to version 0.1.1.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19328

Affected Products

Skill-Ninja-Mcp-Server