CVE-2026-19368 PUBLISHED

PV-Bhat gemsuite-mcp gemini_search unified-gemini.ts path traversal

Assigner: VulDB
Reserved: 09.08.2026 Published: 09.08.2026 Updated: 09.08.2026

A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/gemini_reason/gemini_process/gemini_analyze. The manipulation of the argument file_path/file_paths results in path traversal. The attack must be initiated from a local position. The project was informed of the problem early through an issue report but has not responded yet.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
CVSS Score: 4.8

Product Status

Vendor PV-Bhat
Product gemsuite-mcp
Versions
  • Version 1.0.0 is affected

Credits

  • gongyanyu05 (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Path Traversal CWE