What is CVE-2026-19323?
A path traversal vulnerability has been identified in earlier versions of the `azer react-analyzer-mcp` package, specifically within the `analyze-project` component's handling of the `projectName` argument. This flaw in the `generateProjectDocs` function could allow an attacker to read arbitrary files on the server. Users are strongly advised to update to the latest patched version immediately.
Azərbaycanca: `azer react-analyzer-mcp` paketinin əvvəlki versiyalarında `analyze-project` komponentində `projectName` arqumentinin düzgün yoxlanılmaması nəticəsində path traversal zəifliyi aşkarlanıb. Bu boşluq uzaqdan hücum edən şəxsə `generateProjectDocs` funksiyası vasitəsilə serverdə fayl oxumasına imkan verə bilər. Təsirə məruz qalan sistemlərdə təcili olaraq ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which function in the `azer react-analyzer-mcp` package is affected by CVE-2026-19323?
This vulnerability is a path traversal flaw in the `generateProjectDocs` function that could allow reading arbitrary files on the server.
How can the exploitation of CVE-2026-19323 be prevented?
Users are strongly advised to update the `azer react-analyzer-mcp` package to the latest patched version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.