PT-2026-96003 · Ace-Mcp · Ace-Mcp

·

CVE-2026-94046

·

Published

2026-09-20

·

Updated

2026-09-20

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions 0215AndrewFeng ACE-MCP versions prior to 4.10.9
Description A path traversal issue exists in the MCP Tool component within the get file snippet() function of the getFileSnippet.ts file. This flaw allows a remote attacker to access files outside the intended directory by manipulating the projectRootPath and filePath arguments. The issue occurs because the isPathInsideProjectRoot validation only prevents the filePath from escaping the projectRootPath, but it does not validate the projectRootPath itself, which is provided as untrusted client input.
Recommendations As a temporary workaround, restrict or avoid using the projectRootPath and filePath arguments in the get file snippet() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94046

Affected Products

Ace-Mcp