CVE-2026-19368: PV-Bhat gemsuite-mcp gemini_search unified-gemini.ts path traversal
A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component geminisearch/geminireason/geminiprocess/geminianalyze. The manipulation of the argument filepath/filepaths results in path traversal. The attack must be initiated from a local position. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19368?
The severity of CVE-2026-19368 is classified as low with a score of 3.3.
How do I fix CVE-2026-19368?
To fix CVE-2026-19368, validate and sanitize the user input for file_path to prevent path traversal.
What type of vulnerability is CVE-2026-19368?
CVE-2026-19368 is a path traversal vulnerability.
Which software is affected by CVE-2026-19368?
CVE-2026-19368 affects the PV-Bhat gemsuite-mcp version 1.0.0.
What functionality is impacted by CVE-2026-19368?
CVE-2026-19368 impacts some unknown functionality within the file src/handlers/unified-gemini.ts.