What is CVE-2026-19038?
A path traversal vulnerability exists in MonomythDevelopment la-forge-mcp 1.0.0 within the `screenshot_element` tool due to improper validation of the `output_name` argument. This may allow a remote attacker to write or overwrite arbitrary files on the system. Developers should urgently update the library or apply strict sanitization to incoming file path arguments.
Azərbaycanca: MonomythDevelopment la-forge-mcp 1.0.0-da `screenshot_element` aləti daxilində `output_name` arqumentinin düzgün yoxlanılmaması path traversal zəifliyinə səbəb olur. Bu, uzaqdan hücum edənə fayl sistemində ixtiyari fayl yazmağa və ya üzə çıxarmasına imkan verə bilər. Tərtibatçılar dərhal kitabxananı yeniləməli və ya daxil olan fayl yolu arqumentlərini ciddi şəkildə sanitizə etməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What specific vulnerability has been found in MonomythDevelopment la-forge-mcp 1.0.0?
A path traversal vulnerability exists in the `screenshot_element` tool due to improper validation of the `output_name` argument, which may allow a remote attacker to write arbitrary files on the system.
What is the recommended mitigation for CVE-2026-19038?
Developers are advised to urgently update the library or apply strict sanitization to incoming file path arguments.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.