AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19330

MEDIUM · CVSS 5.3 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-09 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability in angrysky56 advanced-reasoning-mcp 1.0.0 allows for path traversal through the create_system_json/create_library functions in src/index.ts, enabling an attacker with local access to manipulate file paths. This could lead to unauthorized access to sensitive files within the system. Organizations using this software should prioritize remediation, particularly those with local user access controls that may be exploited.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19330
Severity
MEDIUM
CVSS
5.3
EPSS
0.14%

Original NVD Description

A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to get_system_json/switch_memory_library of the file src/index.ts. This manipulation causes path traversal. The attack requires local access. The project was informed of the problem early through an issue report but has not responded yet.