CVE-2026-19338

A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path traversal. The attack must be carried out locally.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-09 07:17

Updated : 2026-08-12 20:59


NVD link : CVE-2026-19338

Mitre link : CVE-2026-19338

CVE.ORG link : CVE-2026-19338


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')