PT-2026-35586 · Ef10007 · Mlops Mcp

Smallw

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-7213

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A vulnerability was detected in ef10007 MLOps MCP 1.0.0. This impacts an unknown function of the file fastmcp server.py of the component save file Tool. The manipulation of the argument filename/destination results in path traversal. The attack may be performed from remote. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-7213

Affected Products

Mlops Mcp