SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86439

HIGH · CVSS 8.8 EPSS 0.75% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Versions prior to 0.30.0 of the MCP tool are vulnerable due to inadequate validation of filesystem paths in command arguments, enabling attackers to exploit directory traversal sequences. This flaw allows unauthorized file access, including reading, creating, overwriting, and deleting files outside the designated project directory. Organizations using affected versions should prioritize patching to mitigate the risk of data exposure and potential system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86439
Severity
HIGH
CVSS
8.8
EPSS
0.75%

Original NVD Description

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server process.