PT-2026-82805 · Maa Ai · Maamcp

·

CVE-2026-81847

·

Published

2026-08-27

·

Updated

2026-08-28

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MAA-AI MaaMCP versions prior to 1.1.1.dev6+g2e4a41287
Description A path traversal issue exists in the save pipeline() and load pipeline() functions within the pipeline tools.py file. This flaw allows a remote attacker to perform a manipulation that results in unauthorized access to files or directories outside the intended folder. Path traversal is a technique used to access files and directories that are stored outside the web root folder by manipulating variables such as file paths.
Recommendations Deploy patch c93ef45cba75295eba26d9ff1ffb9202a91c6150 for versions prior to 1.1.1.dev6+g2e4a41287. As a temporary workaround, restrict the use of the save pipeline() and load pipeline() functions in pipeline tools.py to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81847

Affected Products

Maamcp