PT-2026-36006 · Getsimpletool · Mcpo-Simple-Server

Largew

·

Published

2026-04-29

·

Updated

2026-04-30

·

CVE-2026-7404

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions getsimpletool mcpo-simple-server versions prior to 0.2.1
Description A relative path traversal issue exists in the delete shared prompt() function within the src/mcpo simple server/services/prompt manager/base manager.py file. This occurs due to improper manipulation of the detail argument, allowing a remote attacker to initiate an attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the delete shared prompt() function.

Exploit

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7404
GHSA-3JMQ-QHG3-F58J

Affected Products

Mcpo-Simple-Server