MEDIUM
elinsky
CVE published 2026-04-28
CVE-2026-7319
A path traversal vulnerability has been identified in elinsky execution-system-mcp 0.1.0. The issue lies in the _get_context_file_path function within src/execution_system_mcp/server.py, specifically in the add_action Tool. This vulnerability allows for the manipulation of the context argument, potentially leading to unauthorized access to sensitive files. The attack can be initiated remotely, and an expl [truncated]