What is CVE-2026-19372?
A path traversal vulnerability has been identified in the upload_document component's fs.readFileSync function within the Handwriting-OCR MCP server version 0.1.0. By manipulating the File argument, an attacker can potentially read unauthorized files on the local file system. Applying the upcoming security update is recommended.
Azərbaycanca: Handwriting-OCR MCP server 0.1.0 versiyasının upload_document komponentində fs.readFileSync funksiyasında argument manipulyasiyası nəticəsində path traversal zəifliyi aşkar edilib. Bu zəiflik təcavüzkara lokal fayl sistemi üzərində icazəsiz faylları oxumağa imkan verə bilər. Təhlükəsizlik qrupunun təqdim edəcəyi yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which version of the Handwriting-OCR MCP server is affected by CVE-2026-19372?
This path traversal vulnerability has been identified in version 0.1.0 of the Handwriting-OCR MCP server.
What action can an attacker perform by exploiting CVE-2026-19372?
By manipulating the File argument in the upload_document component, an attacker can read unauthorized files on the local file system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.