What is CVE-2026-19366?
A path traversal vulnerability has been identified in NocteDefensor LudusMCP versions up to 1.0.24, specifically within the `insert_creds_range_config` function in the `src/tools/insertCredsRangeConfig.ts` file. The flaw allows restricted attackers to manipulate the `configPath` or `outputPath` arguments, potentially leading to unauthorized filesystem operations. Users are advised to apply the security patch or temporarily disable the product until an update is available.
Azərbaycanca: NocteDefensor LudusMCP proqramının 1.0.24 versiyasına qədər olan versiyalarında `src/tools/insertCredsRangeConfig.ts` faylındakı `insert_creds_range_config` funksiyasında path traversal zəifliyi aşkarlanıb. Bu zəiflik `configPath` və ya `outputPath` arqumentlərinin manipulyasiyası ilə məhdud hücumlar nəticəsində fayl sistemi üzərində icazəsiz əməliyyatlara səbəb ola bilər. İstifadəçilərə təhlükəsizlik yeniləməsini tətbiq etmək və ya məhsulu müvəqqəti olaraq deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of NocteDefensor LudusMCP are affected by the CVE-2026-19366 path traversal vulnerability?
Versions up to 1.0.24.
In which function and file does the CVE-2026-19366 vulnerability reside in NocteDefensor LudusMCP?
In the `insert_creds_range_config` function within the `src/tools/insertCredsRangeConfig.ts` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.