PatchSiren

elie CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW elie CVE published 2026-04-28

CVE-2026-7318

A path traversal vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. The manipulation of the argument topic results in path traversal. Local attack is a requirement. The vulnerability is caused by improper handling of the topic argument in the search_papers function of research_server.py, leading to a path traversal issue [truncated]