What is CVE-2026-19288?
CVE-2026-19288 is a path traversal vulnerability in the `importRiveFile` flow within `importRiveFile.ts` of astralisone rive-mcp-server-core, caused by improper handling of the `libraryId` argument. This could allow a remote attacker to manipulate file paths on the affected component. Users are advised to update to the latest patched version immediately.
Azərbaycanca: CVE-2026-19288 astralisone rive-mcp-server-core proqramında `importRiveFile.ts` faylındakı `importRiveFile` axınında `libraryId` arqumentinin manipulyasiyası nəticəsində path traversal zəifliyidir. Bu, uzaqdan hücum edənə təsirə məruz qalmış komponentdə fayl yollarını manipulyasiya etməyə imkan verə bilər. İstifadəçilərə dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What software is affected by CVE-2026-19288?
This vulnerability affects the astralisone rive-mcp-server-core software.
What should users do to protect against CVE-2026-19288?
Users are advised to update to the latest patched version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.