PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66004 ahujasid CVE debrief

CVE-2026-66004 is a path traversal vulnerability in BlenderMCP's download_polyhaven_asset method. The vulnerability allows attackers to write arbitrary files by injecting traversal sequences in API response include keys. This could lead to persistent code execution via malicious paths like '../../.bashrc'. The CVE record was published on 2026-07-24T15:19:07.050Z and has not been modified since then. Defenders should review and verify the presence of the vulnerable method, perform inventory checks, and monitor for suspicious API requests.

Vendor
ahujasid
Product
blender-mcp
CVSS
MEDIUM 6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-24
Original CVE updated
2026-07-27
Advisory published
2026-07-24
Advisory updated
2026-07-27

Who should care

Defenders of systems using BlenderMCP should review and verify the presence of the vulnerable download_polyhaven_asset method, perform inventory checks, and monitor for suspicious API requests. This includes operators, platform administrators, vulnerability management teams, and security teams responsible for ensuring the security and integrity of affected systems.

Technical summary

CVE-2026-66004 is a path traversal vulnerability in BlenderMCP's download_polyhaven_asset method. Attackers can inject traversal sequences in API response include keys to write arbitrary files, potentially achieving persistent code execution via malicious paths like '../../.bashrc'. The vulnerability has a CVSS score of 6 and is classified as MEDIUM severity. Defenders should focus on verifying affected scope, restricting API access, and monitoring for suspicious patterns.

Defensive priority

Medium priority due to CVSS score of 6 and potential for code execution. Defenders should prioritize verification of affected scope, restrict API access, and implement compensating controls.

Recommended defensive actions

  • Verify BlenderMCP version and apply commit 30a3308 or later
  • Restrict API access to download_polyhaven_asset method
  • Monitor API requests for suspicious patterns
  • Perform inventory checks for affected systems
  • Implement compensating controls for file system access
  • Review and validate vendor remediation guidance
  • Track exceptions and retest remediated assets

Evidence notes

Evidence is based on limited source detail from Vulncheck and NVD. Further verification is needed to confirm affected scope and validate vendor remediation. Defenders should verify the presence of vulnerable BlenderMCP deployments, review API access controls, and monitor for suspicious activity. Evidence limits may impact the accuracy of affected scope and remediation guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T15:19:07.050Z and has not been modified since then.