AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19046

LOW · CVSS 3.3 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A path traversal vulnerability exists in the NocteDefensor LudusMCP application, specifically within the ludus_environment_guides_search component, affecting versions up to 1.0.24. This flaw allows local attackers to manipulate the guide_name argument, potentially exposing sensitive files on the system. Organizations using this software should prioritize remediation, especially if they have local users with untrusted access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19046
Severity
LOW
CVSS
3.3
EPSS
0.14%

Original NVD Description

A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name leads to path traversal. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet.