PatchSiren

03-lovepreetSingh CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM 03-lovepreetSingh CVE published 2026-09-20

CVE-2026-94044

A path traversal vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546, affecting the create_file function in app/api/mcp/route.ts. The attack can be launched remotely and a public exploit is available. However, the product does not use versioning, making it difficult to determine affected and unaffected releases.