What is CVE-2026-19371?
CVE-2026-19371 is a path traversal vulnerability in Nikolaibibo claude-comfyui-mcp 1.0.0, affecting the `copyFileSync` function in `src/tools/utils.ts` via the `comfy_upload_image` component due to improper validation of the `image_path` argument. This allows local attackers to access sensitive files outside the intended directory. Affected users should update the project immediately or apply a patch to sanitize user input.
Azərbaycanca: CVE-2026-19371, Nikolaibibo claude-comfyui-mcp 1.0.0 versiyasında `comfy_upload_image` komponentində `src/tools/utils.ts` faylındakı `copyFileSync` funksiyasında `image_path` arqumentinin düzgün yoxlanılmaması nəticəsində baş verən path traversal zəifliyidir. Bu, yerli təcavüzkarın həssas fayllara icazəsiz giriş əldə etməsinə imkan verir. Təsirə məruz qalan istifadəçilər dərhal layihəni yeniləməli və ya giriş yoxlamalarını gücləndirmək üçün müvəqqəti patch tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ1
In which function and file does CVE-2026-19371 cause a path traversal vulnerability?
The `copyFileSync` function in `src/tools/utils.ts` due to improper validation of the `image_path` argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.