What is CVE-2026-19336?
A path traversal vulnerability was found in Pimzino spec-workflow-mcp up to version 2.2.6, affecting the `ApprovalStorage.createApproval` function in `src/tools/approvals.ts` via manipulation of the `categoryName` argument. The attack requires local access.
Azərbaycanca: Pimzino spec-workflow-mcp 2.2.6 və aşağı versiyalarında `src/tools/approvals.ts` faylında path traversal zəifliyi aşkar edilib. Bu, `ApprovalStorage.createApproval` funksiyasında `categoryName` parametri üzərində manipulyasiya nəticəsində baş verir və yalnız lokal girişlə istismar oluna bilər.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which component of Pimzino spec-workflow-mcp was CVE-2026-19336 discovered?
The vulnerability was discovered in the `ApprovalStorage.createApproval` function within the `src/tools/approvals.ts` file.
What level of access is required to exploit CVE-2026-19336?
Exploitation of this vulnerability requires local access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.