CVE-2026-19370: bartekke8it56w2 new-mcp geminithinking index.ts fs.readFileSync path traversal
A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the argument sessionCommand/sessionPath causes path traversal. The attack requires local access. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19370?
The severity of CVE-2026-19370 is classified as medium with a score of 5.3.
What type of vulnerability is CVE-2026-19370?
CVE-2026-19370 is a path traversal vulnerability affecting the new-mcp geminithinking component.
How does CVE-2026-19370 exploit the system?
CVE-2026-19370 exploits the system by manipulating the arguments of fs.readFileSync and related functions to perform path traversal.
How do I fix CVE-2026-19370?
To fix CVE-2026-19370, ensure proper validation and sanitization of input paths used in the file operations.
Is CVE-2026-19370 exploitable locally?
Yes, CVE-2026-19370 requires local access to exploit the path traversal vulnerability.