CVE-2026-19287: abrinsmead mindpilot-mcp HistoryService path traversal
A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This manipulation of the argument ID causes path traversal. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19287?
The severity of CVE-2026-19287 is rated as medium, with a score of 5.3.
How do I fix CVE-2026-19287?
To fix CVE-2026-19287, update the abrinsmead mindpilot-mcp to the latest version that addresses the path traversal vulnerability.
What component is affected by CVE-2026-19287?
CVE-2026-19287 affects the HistoryService component of abrinsmead mindpilot-mcp.
What type of vulnerability is CVE-2026-19287?
CVE-2026-19287 is classified as a Path Traversal vulnerability.
What conditions are required to exploit CVE-2026-19287?
Exploitation of CVE-2026-19287 requires local access to the system where the HistoryService component is running.