CVE-2026-79622: dekdee adobe-xd-mcp file-access-from-request Endpoint xd-parser.ts path traversal
A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the file src/parsers/xd-parser.ts of the component file-access-from-request Endpoint. Executing a manipulation of the argument outputFile/outputDir can lead to path traversal. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments of dekdee/adobe-xd-mcp 1.0.0 that expose the file-access-from-request endpoint remotely are exposed to remote attack. No authentication or user interaction is required according to the supplied severity vector.
What does an attacker need to exploit this issue?
An attacker needs to submit manipulated outputFile or outputDir argument values to the affected endpoint. The attack has low complexity and a public exploit is available.
Is a vendor fix or workaround available?
The provided information does not identify a fix or workaround. The project was notified through an issue report but had not responded at the time of publication.