AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19370

MEDIUM · CVSS 5.3 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-09 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A path traversal vulnerability exists in the file handling functions of the geminithinking component in new-mcp version 0.1.0, allowing local attackers to manipulate file paths through the sessionCommand/sessionPath arguments. This could lead to unauthorized file access or modification within the affected system. Developers and system administrators using this component should prioritize addressing this vulnerability to mitigate potential local exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19370
Severity
MEDIUM
CVSS
5.3
EPSS
0.14%

Original NVD Description

A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the argument sessionCommand/sessionPath causes path traversal. The attack requires local access. The project was informed of the problem early through an issue report but has not responded yet.