What is CVE-2026-19328?
CVE-2026-19328 is a path traversal vulnerability identified in aktsmm skill-ninja-mcp-server version 0.1.0, affecting functions in the `src/installer.ts` file. By manipulating the `workspacePath` argument, a local attacker could potentially exploit this flaw. Users are advised to update to the latest patched version to mitigate the risk.
Azərbaycanca: CVE-2026-19328 aktsmm skill-ninja-mcp-server 0.1.0 versiyasında aşkarlanmış path traversal zəifliyidir. `src/installer.ts` faylındakı müvafiq funksiyalarda `workspacePath` arqumentinin manipulyasiyası nəticəsində local attack mümkündür. Təsirə məruz qalmamaq üçün proqram təminatını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which file contains the CVE-2026-19328 vulnerability?
This path traversal vulnerability was identified in the `src/installer.ts` file of aktsmm skill-ninja-mcp-server version 0.1.0.
What type of attack is possible when exploiting CVE-2026-19328?
A local attack is possible by manipulating the `workspacePath` argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.