What is CVE-2026-19324?
A path traversal vulnerability has been identified in the fs.promises.readFile function within callback-server.ts of HelloGGX shadcn-vue-mcp, via manipulation of the 'filepath' argument. This could allow an attacker to read unauthorized files on the server.
Azərbaycanca: HelloGGX shadcn-vue-mcp proqramının callback-server.ts faylındakı fs.promises.readFile funksiyasında 'filepath' arqumenti üzərindən path traversal zəifliyi aşkar edilib. Bu, təcavüzkarın serverdə icazəsiz faylları oxumasına şərait yarada bilər.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What type of vulnerability has been identified in the shadcn-vue-mcp product?
A path traversal vulnerability has been identified in the fs.promises.readFile function within callback-server.ts of shadcn-vue-mcp, via manipulation of the 'filepath' argument.
What can an attacker achieve by exploiting CVE-2026-19324?
An attacker could read unauthorized files on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.