CVE-2026-19366: NocteDefensor LudusMCP insert_creds_range_config insertCredsRangeConfig.ts path traversal
A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the component insertcredsrangeconfig. Executing a manipulation of the argument configPath/outputPath can lead to path traversal. The attack is restricted to local execution. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19366?
CVE-2026-19366 has a severity rating of medium with a score of 5.3.
How do I fix CVE-2026-19366?
To fix CVE-2026-19366, update NocteDefensor LudusMCP to the latest version that addresses this vulnerability.
What does CVE-2026-19366 affect?
CVE-2026-19366 affects the insert_creds_range_config component in NocteDefensor LudusMCP up to version 1.0.24.
What kind of vulnerability is CVE-2026-19366?
CVE-2026-19366 is a path traversal vulnerability that allows attackers to manipulate file paths within the application.
What can be exploited in CVE-2026-19366?
CVE-2026-19366 can be exploited by manipulating the configPath/outputPath argument which can lead to unauthorized access to file paths.