CVE-2026-19270: Hulupeep mcp-ui-probe Journey/Usage JourneyStorage.ts usage_stats path traversal
A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function getjourney/deletejourney/analyzejourney/usagestats of the file src/journey/JourneyStorage.ts of the component Journey/Usage. The manipulation of the argument journeyId/filename results in path traversal. The attack requires a local approach. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19270?
The severity of CVE-2026-19270 is classified as medium with a score of 5.3.
What systems are affected by CVE-2026-19270?
CVE-2026-19270 affects versions of Hulupeep mcp-ui-probe up to 0.2.0.
How do I mitigate CVE-2026-19270?
To mitigate CVE-2026-19270, update to a fixed version of Hulupeep mcp-ui-probe beyond 0.2.0.
What kind of vulnerability is CVE-2026-19270?
CVE-2026-19270 is classified as a path traversal vulnerability.
What can an attacker achieve with CVE-2026-19270?
An attacker can manipulate the input arguments to access unauthorized file paths using CVE-2026-19270.