CyberRota Analysis
AI-GeneratedThe vulnerability in angrysky56 advanced-reasoning-mcp 1.0.0 allows for path traversal through the create_system_json/create_library functions in src/index.ts, enabling an attacker with local access to manipulate file paths. This could lead to unauthorized access to sensitive files within the system. Organizations using this software should prioritize remediation, particularly those with local user access controls that may be exploited.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to get_system_json/switch_memory_library of the file src/index.ts. This manipulation causes path traversal. The attack requires local access. The project was informed of the problem early through an issue report but has not responded yet.