PT-2026-35831 · Unknown · Mcp-Project
Littlew
·
Published
2026-04-28
·
Updated
2026-04-29
·
CVE-2026-7318
CVSS v3.1
5.9
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
elie mcp-project version 0.1.0
Description
A path traversal issue exists in the
search papers() function within the research server.py file. This occurs when the topic argument is manipulated, allowing for unauthorized file system access. Local access is required to exploit this flaw.Recommendations
As a temporary workaround, restrict the use of the
topic argument in the search papers() function to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Project