PT-2026-36006 · Getsimpletool · Mcpo-Simple-Server
Largew
·
Published
2026-04-29
·
Updated
2026-04-30
·
CVE-2026-7404
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
getsimpletool mcpo-simple-server versions prior to 0.2.1
Description
A relative path traversal issue exists in the
delete shared prompt() function within the src/mcpo simple server/services/prompt manager/base manager.py file. This occurs due to improper manipulation of the detail argument, allowing a remote attacker to initiate an attack.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting access to the
delete shared prompt() function.Exploit
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcpo-Simple-Server