PT-2026-69279 · Automateyournetwork · Mcpyats
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
automateyournetwork MCPyATS versions prior to 0.1.5
Description
A path traversal issue exists in the
generate mermaid markdown component within the processGenerateRequest() function located in the mcp servers/mermaid/index.ts file. A local attacker can manipulate the folder/name argument to access files or directories outside the intended scope. Path traversal is a technique used to access files and directories that are stored outside the web root folder by manipulating variables such as filenames and file paths.Recommendations
Update automateyournetwork MCPyATS to version 0.1.5 or later.
As a temporary mitigation, restrict local access to the
processGenerateRequest() function.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcpyats