PT-2026-36546 · Flux159 · Mcp-Game-Asset-Gen
Eternity
·
Published
2026-05-01
·
Updated
2026-05-05
·
CVE-2026-7594
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Flux159 mcp-game-asset-gen version 0.1.0
Description
A path traversal issue exists in the MCP Interface component within the
image to 3d async() function of the src/index.ts file. This flaw allows remote attackers to perform path traversal by manipulating the statusFile argument.Recommendations
As a temporary workaround, restrict the use of the
image to 3d async() function or carefully validate the statusFile argument to prevent unauthorized file system access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Game-Asset-Gen