What is CVE-2026-19365?
A path traversal vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0, specifically in the "upscale_images" component within `src/index.ts`, via improper handling of the `output_path` argument. This allows local attackers to read arbitrary files on the system. Immediate patching is recommended to prevent unauthorized file access.
Azərbaycanca: Ichigo3766 image-gen-mcp 0.1.0 versiyasında "upscale_images" komponentində path traversal zəifliyi aşkar edilib. Bu, `src/index.ts` faylında `output_path` arqumentinin düzgün yoxlanılmaması səbəbindən yerli şəbəkədə fayl sisteminə icazəsiz girişə imkan verir. Təhlükəsizlik üçün dərhal patching tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which component was CVE-2026-19365 identified?
The vulnerability exists in the "upscale_images" component of Ichigo3766 image-gen-mcp 0.1.0, located in `src/index.ts`.
What type of vulnerability is CVE-2026-19365?
It is a path traversal vulnerability caused by improper handling of the `output_path` argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.