PT-2026-95979 · Unknown · Mcp-File-Analyzer

·

CVE-2026-94037

·

Published

2026-09-20

·

Updated

2026-09-22

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions 00Kisumi00 mcp-file-analyzer versions up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405
Description A path traversal issue exists in the analyze csv data MCP tool within the ControlFlowNode() function of the main.py file. This occurs when the filename argument is manipulated, allowing for remote exploitation.
Recommendations As a temporary workaround, restrict the use of the filename argument in the ControlFlowNode() function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94037

Affected Products

Mcp-File-Analyzer