What is CVE-2026-19330?
CVE-2026-19330 is a path traversal vulnerability in angrysky56 advanced-reasoning-mcp version 1.0.0, affecting the create_system_json/create_library functions in src/index.ts. It allows local attackers to manipulate directory paths. Users should implement input validation for the affected functions immediately.
Azərbaycanca: CVE-2026-19330, angrysky56 advanced-reasoning-mcp 1.0.0 versiyasında aşkarlanan path traversal zəifliyidir. src/index.ts faylındakı create_system_json/create_library funksiyaları vasitəsilə lokal şəbəkədə kataloq keçidinə imkan verir. İstifadəçilərə dərhal müvafiq funksiyalar üçün giriş yoxlamalarını tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which product and version was CVE-2026-19330 discovered?
The vulnerability was discovered in angrysky56 advanced-reasoning-mcp version 1.0.0.
What mitigation is recommended for CVE-2026-19330?
Users are advised to immediately implement input validation for the create_system_json/create_library functions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.