Sceawere
Vulnerability Detail
CVE-2026-19287UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Mindpilot-MCP HistoryService Path Traversal
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- abrinsmead
- Product
- mindpilot-mcp
- Attack Type
- Path Traversal
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This manipulation of the argument ID causes path traversal. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-08T14:16:22.913Z",
"pubdate": "2026-08-08T14:16:22.913Z",
"executiveSummary": "A path traversal vulnerability has been identified in abrinsmead mindpilot-mcp version 0.5.0, specifically within the HistoryService component.\nThe vulnerability arises from the insecure handling of the argument ID, which allows malicious local manipulation to traverse the file system.\nSuccessful exploitation of this flaw can lead to unauthorized access to sensitive local files and data disclosure depending on the privileges of the executing process.\nThe risk implications include potential compromise of confidentiality by exposing arbitrary files accessible to the application context.\nAttacker capabilities are constrained by the requirement for local access to the system to launch the attack.\nThe project was informed of the issue via an issue report but has not provided an official response or patch at this time.",
"technicalDetails": "The vulnerability resides in the HistoryService component of abrinsmead mindpilot-mcp version 0.5.0.\nThe root cause is improper neutralization of input supplied via the argument ID, which is directly utilized in file system operations without adequate sanitization or boundary validation.\nThis design flaw permits directory traversal sequences (such as dot-dot-slash patterns) to be injected into the ID parameter, enabling access to resources outside the intended operational directory.\nThe attack flow begins locally, where an attacker crafts a malicious input string containing path traversal sequences directed at the vulnerable argument ID processed by HistoryService.\nUpon receiving the input, the component fails to restrict the file path resolution securely, allowing the underlying file system API to traverse directories.\nAuthentication requirements, privilege requirements, and network exposure are bounded by the local execution context; the attack must be launched locally against the affected component.\nThe payload behavior involves navigating the directory hierarchy to read unauthorized files accessible to the application's permission scope.\nThe post-exploitation impact includes the potential unauthorized disclosure of sensitive system or application files, thereby undermining the confidentiality boundaries of the affected host environment."
}