A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-s…
低危 CVSS 3.3
摘要
A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-server.ts. This manipulation of the argument filepath causes path traversal. The attack is restricted to local execution. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was in…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/HelloGGX/shadcn-vue-mcp/
- https://github.com/HelloGGX/shadcn-vue-mcp/issues/14
- https://vuldb.com/cve/CVE-2026-19324
- https://vuldb.com/submit/865241
- https://vuldb.com/vuln/387158
- https://vuldb.com/vuln/387158/cti
时间线
- nvd_ingest NVD