CyberRota Analysis
AI-GeneratedA path traversal vulnerability exists in the file handling functions of the geminithinking component in new-mcp version 0.1.0, allowing local attackers to manipulate file paths through the sessionCommand/sessionPath arguments. This could lead to unauthorized file access or modification within the affected system. Developers and system administrators using this component should prioritize addressing this vulnerability to mitigate potential local exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the argument sessionCommand/sessionPath causes path traversal. The attack requires local access. The project was informed of the problem early through an issue report but has not responded yet.