A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-s…
Low CVSS 3.3
Summary
A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-server.ts. This manipulation of the argument filepath causes path traversal. The attack is restricted to local execution. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was in…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/HelloGGX/shadcn-vue-mcp/
- https://github.com/HelloGGX/shadcn-vue-mcp/issues/14
- https://vuldb.com/cve/CVE-2026-19324
- https://vuldb.com/submit/865241
- https://vuldb.com/vuln/387158
- https://vuldb.com/vuln/387158/cti
Timeline
- nvd_ingest NVD