LOW
elie
CVE published 2026-04-28
CVE-2026-7318
A path traversal vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. The manipulation of the argument topic results in path traversal. Local attack is a requirement. The vulnerability is caused by improper handling of the topic argument in the search_papers function of research_server.py, leading to a path traversal issue [truncated]