Skip to content

MCPA-2026-0060

lowpath-traversalCVSS 5.3

mcp-ui-probe journey storage path traversal (CVE-2026-19270)

mcp-ui-probe (npm) up to 0.2.0: the get_journey/delete_journey/analyze_journey/usage_stats functions in src/journey/JourneyStorage.ts pass the journeyId/filename arguments into filesystem paths without sanitization, allowing path traversal outside the journey storage directory. The project was informed through a public issue but has not responded and no fixed release exists, so the range is recorded as last_affected 0.2.0 per the public advisory.

Affected packages

EcosystemPackageAffected versions
npmmcp-ui-probe
>= 0, <= 0.2.0

Identifiers

CVE-2026-19270GHSA-h8jj-pqww-5m4wCWE-22

References

Timeline

  • Published: 2026-08-08

← All advisories