CVE-2026-19372: Handwriting-OCR handwriting-ocr-mcp-server upload_document index.ts fs.readFileSync path traversal
A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component uploaddocument. Performing a manipulation of the argument File results in path traversal. Attacking locally is a requirement. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19372?
The severity of CVE-2026-19372 is rated as medium with a score of 5.3.
What vulnerabilities are associated with CVE-2026-19372?
CVE-2026-19372 is associated with a path traversal vulnerability in the Handwriting-OCR handwriting-ocr-mcp-server.
How does CVE-2026-19372 affect the Handwriting-OCR handwriting-ocr-mcp-server?
CVE-2026-19372 allows an attacker to manipulate the argument File in the fs.readFileSync function to perform path traversal attacks.
How do I fix CVE-2026-19372?
To fix CVE-2026-19372, ensure proper validation and sanitization of file input to prevent path traversal.
Which versions of Handwriting-OCR are affected by CVE-2026-19372?
CVE-2026-19372 affects Handwriting-OCR handwriting-ocr-mcp-server version 0.1.0.