MCPA-2026-0060
lowpath-traversalCVSS 5.3
mcp-ui-probe journey storage path traversal (CVE-2026-19270)
mcp-ui-probe (npm) up to 0.2.0: the get_journey/delete_journey/analyze_journey/usage_stats functions in src/journey/JourneyStorage.ts pass the journeyId/filename arguments into filesystem paths without sanitization, allowing path traversal outside the journey storage directory. The project was informed through a public issue but has not responded and no fixed release exists, so the range is recorded as last_affected 0.2.0 per the public advisory.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | mcp-ui-probe | >= 0, <= 0.2.0 |
Identifiers
CVE-2026-19270GHSA-h8jj-pqww-5m4wCWE-22
References
- advisory https://github.com/advisories/GHSA-h8jj-pqww-5m4w
- web https://nvd.nist.gov/vuln/detail/CVE-2026-19270
- web https://github.com/Hulupeep/mcp-ui-probe/issues/1
Timeline
- Published: 2026-08-08