A path traversal vulnerability has been identified in eiceblue spire-pdf-mcp-server version 0.1.1. The vulnerability exists in the get_pdf_path function of the src/spire_pdf_mcp/server.py file. An attacker can remotely exploit this vulnerability by manipulating the filepath argument, potentially leading to unauthorized access to sensitive files. This vulnerability has a CVSS score of 5.5 and a severity of [truncated]
A path traversal vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0, affecting the get_doc_path function in src/spire_doc_mcp/api/base.py. The vulnerability allows remote attackers to manipulate the document_name argument, potentially leading to unauthorized access to sensitive files. This type of vulnerability can be particularly problematic as it may allow attackers to access sensitive in [truncated]