CVE-2026-19046: NocteDefensor LudusMCP ludus_environment_guides_search ludusEnvironmentGuidesSearch.ts path traversal
A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludusenvironmentguidessearch. Such manipulation of the argument guidename leads to path traversal. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19046?
The severity of CVE-2026-19046 is classified as low, with a score of 3.3.
What type of vulnerability is CVE-2026-19046?
CVE-2026-19046 is a path traversal vulnerability.
How can I mitigate CVE-2026-19046?
To mitigate CVE-2026-19046, it is recommended to update NocteDefensor LudusMCP to the latest version.
Which component is affected by CVE-2026-19046?
The affected component for CVE-2026-19046 is ludus_environment_guides_search.
What causes the vulnerability in CVE-2026-19046?
CVE-2026-19046 is caused by improper handling of the 'guide_name' argument which leads to path traversal.