PT-2026-95979 · Unknown · Mcp-File-Analyzer
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
00Kisumi00 mcp-file-analyzer versions up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405
Description
A path traversal issue exists in the
analyze csv data MCP tool within the ControlFlowNode() function of the main.py file. This occurs when the filename argument is manipulated, allowing for remote exploitation.Recommendations
As a temporary workaround, restrict the use of the
filename argument in the ControlFlowNode() function to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-File-Analyzer