AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19288

MEDIUM · CVSS 5.3 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-08 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The astralisone rive-mcp-server-core is vulnerable to a local path traversal attack due to improper handling of the libraryId argument in the importRiveFile component. This could allow an attacker to access restricted files on the system. Organizations using this software should prioritize remediation, especially if they rely on local access controls, as the vulnerability could lead to unauthorized data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19288
Severity
MEDIUM
CVSS
5.3
EPSS
0.14%

Original NVD Description

A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFile.ts of the component importRiveFile Flow. Such manipulation of the argument libraryId leads to path traversal. The attack needs to be performed locally. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.