Skip to content

MCPA-2026-0017

lowpath-traversalCVSS 3.3

LudusMCP ludus_environment_guides_search path traversal via guide_name (CVE-2026-19046)

LudusMCP (npm: ludus-mcp) up to and including 1.0.24 is vulnerable to path traversal: src/tools/ludusEnvironmentGuidesSearch.ts (component ludus_environment_guides_search) uses the attacker-influenced guide_name argument to build a filesystem path without sanitization, so a poisoned tool call can read files outside the guides directory. The maintainer was notified via a public issue but no fixed release exists as of 2026-08-06.

Affected packages

EcosystemPackageAffected versions
npmludus-mcp
>= 0, <= 1.0.24

Identifiers

CVE-2026-19046GHSA-6j8j-xrrf-px36CWE-22

References

Timeline

  • Published: 2026-08-06

← All advisories