PT-2026-69259 · Jane Xiaoer · Skill-Vision-Control

·

CVE-2026-19335

·

Published

2026-08-09

·

Updated

2026-08-13

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Jane-xiaoer skill-vision-control versions prior to 1.3.1
Description A path traversal issue exists in the getSkillVersionsDir() function within the src/svc/utils/config.ts file. This occurs when the skillName argument is manipulated, allowing an attacker to access files or directories outside the intended folder. This attack can only be executed from a local environment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary mitigation, restrict access to the getSkillVersionsDir() function to prevent unauthorized path manipulation.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19335

Affected Products

Skill-Vision-Control