What is CVE-2026-66004?
CVE-2026-66004 is a path traversal vulnerability in the download_polyhaven_asset method of BlenderMCP, allowing attackers to write arbitrary files by injecting traversal sequences into API response include keys. It can be exploited through MITM attacks or prompt injection. Users should update to commit 30a3308 or later to mitigate the issue.
Azərbaycanca: CVE-2026-66004: BlenderMCP proqramında "download_polyhaven_asset" metodunda aşkarlanan path traversal zəifliyi, API cavablarına daxil edilmiş zərərli keçidlərdən istifadə edərək ixtiyari faylların yazılmasına imkan verir. Bu zəiflik MITM hücumları və ya prompt injection vasitəsilə istismar edilə bilər. Qorunmaq üçün commit 30a3308 və ya daha yeni versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which method of BlenderMCP was the CVE-2026-66004 vulnerability discovered?
This path traversal vulnerability was discovered in the download_polyhaven_asset method of BlenderMCP.
Which version should be updated to in order to mitigate CVE-2026-66004?
To mitigate this vulnerability, users should update to commit 30a3308 or a later version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.