What is CVE-2026-19287?
CVE-2026-19287 is a path traversal vulnerability in the HistoryService component of abrinsmead mindpilot-mcp 0.5.0. It allows local attackers to manipulate the ID argument to access unauthorized files. Users should update to a patched version as soon as it becomes available.
Azərbaycanca: CVE-2026-19287, abrinsmead mindpilot-mcp 0.5.0 versiyasının HistoryService komponentində aşkar edilmiş path traversal zəifliyidir. Bu zəiflik lokal şəbəkədə arqument ID-nin manipulyasiyası ilə sui-istifadəyə imkan verir. Təhlükəsizlik üçün məhsulun yenilənmiş versiyasına keçmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which component of mindpilot-mcp was CVE-2026-19287 discovered?
This vulnerability was discovered in the HistoryService component of mindpilot-mcp.
How is an attack exploiting CVE-2026-19287 carried out?
The attack is carried out by manipulating the ID argument over a local network to exploit the path traversal vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.