CVE-2026-7318 PUBLISHED

elie mcp-project research_server.py search_papers path traversal

Assigner: VulDB
Reserved: 28.04.2026 Published: 28.04.2026 Updated: 28.04.2026

A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. The manipulation of the argument topic results in path traversal. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.1

Product Status

Vendor elie
Product mcp-project
Versions
  • Version 0.1.0 is affected

Credits

  • LittleW (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Path Traversal CWE