PT-2026-69254 · Npm · Advanced-Reasoning-Mcp

·

CVE-2026-19330

·

Published

2026-08-09

·

Updated

2026-08-14

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions angrysky56 advanced-reasoning-mcp version 1.0.0
Description A path traversal issue exists in the file src/index.ts within the functions create system json(), create library(), get system json(), and switch memory library(). Path traversal is a flaw that allows an attacker to access files and directories that are stored outside the intended folder. Exploiting this issue requires local access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict the use of the functions create system json(), create library(), get system json(), and switch memory library() to minimize the risk of exploitation.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19330

Affected Products

Advanced-Reasoning-Mcp