MCPA-2026-0017
lowpath-traversalCVSS 3.3
LudusMCP ludus_environment_guides_search path traversal via guide_name (CVE-2026-19046)
LudusMCP (npm: ludus-mcp) up to and including 1.0.24 is vulnerable to path traversal: src/tools/ludusEnvironmentGuidesSearch.ts (component ludus_environment_guides_search) uses the attacker-influenced guide_name argument to build a filesystem path without sanitization, so a poisoned tool call can read files outside the guides directory. The maintainer was notified via a public issue but no fixed release exists as of 2026-08-06.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | ludus-mcp | >= 0, <= 1.0.24 |
Identifiers
CVE-2026-19046GHSA-6j8j-xrrf-px36CWE-22
References
- advisory https://github.com/advisories/GHSA-6j8j-xrrf-px36
- web https://nvd.nist.gov/vuln/detail/CVE-2026-19046
- report https://github.com/NocteDefensor/LudusMCP/issues/4
Timeline
- Published: 2026-08-06