MEDIUM
03-lovepreetSingh
CVE published 2026-09-20
CVE-2026-94044
A path traversal vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546, affecting the create_file function in app/api/mcp/route.ts. The attack can be launched remotely and a public exploit is available. However, the product does not use versioning, making it difficult to determine affected and unaffected releases.