CVE-2026-19365 PUBLISHED

Ichigo3766 image-gen-mcp upscale_images index.ts path traversal

Assigner: VulDB
Reserved: 08.08.2026 Published: 09.08.2026 Updated: 09.08.2026

A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipulation of the argument output_path leads to path traversal. The attack must be carried out locally. The project was informed of the problem early through an issue report but has not responded yet.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 4.8

Product Status

Vendor Ichigo3766
Product image-gen-mcp
Versions
  • Version 0.1.0 is affected

Credits

  • gongyanyu05 (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Path Traversal CWE