CVE-2026-19038 PUBLISHED

MonomythDevelopment la-forge-mcp screenshot_element Tool index.ts screenshotElement path traversal

Assigner: VulDB
Reserved: 06.08.2026 Published: 06.08.2026 Updated: 06.08.2026

A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file src/index.ts of the component screenshot_element Tool. Such manipulation of the argument output_name leads to path traversal. The attack can be executed remotely. Upgrading to version 1.1.1 is capable of addressing this issue. The name of the patch is 1102172c9adec4a619e241efd6bfb74f5b1f4332. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor MonomythDevelopment
Product la-forge-mcp
Versions
  • Version 1.0.0 is affected
  • Version 1.1.1 is unaffected

Credits

  • gongyanyu (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Path Traversal CWE