CVE-2026-94044: Path Traversal in 03-lovepreetSingh MCP
CVE-2026-94044 is a path traversal vulnerability in the create_file function of the 03-lovepreetSingh MCP project. This flaw allows remote attackers to manipulate file path arguments, potentially accessing unauthorized files. The project lacks versioning, so specific affected versions are unknown. The vulnerability has a medium severity score of 6.9 and an exploit is publicly available. The project maintainers have not responded to the issue report, and no patch or remediation information is currently available.
AI Analysis
Technical Summary
The vulnerability exists in the create_file function within app/api/mcp/route.ts of the 03-lovepreetSingh MCP project up to commit f95d035c5317fad81af9828286631053ccb23546. It allows remote attackers to perform path traversal by manipulating the filePath or content arguments, potentially leading to unauthorized file access. The project does not use versioning, so affected versions cannot be precisely identified. The issue was reported early to the project but remains unaddressed. An exploit is publicly available, but no evidence of active exploitation in the wild is reported.
Potential Impact
Successful exploitation can lead to unauthorized access to files outside the intended directory, which may expose sensitive information or allow further attacks. The vulnerability is remotely exploitable without authentication, increasing risk. However, no confirmed active exploitation is known at this time.
Mitigation Recommendations
No official fix or patch is currently available. Users should monitor the project for updates or advisories. Until a fix is released, restricting access to the vulnerable functionality or implementing external controls to validate and sanitize file path inputs may reduce risk. Patch status is not yet confirmed — check the vendor advisory or project repository for current remediation guidance.
CVE-2026-94044: Path Traversal in 03-lovepreetSingh MCP
Description
CVE-2026-94044 is a path traversal vulnerability in the create_file function of the 03-lovepreetSingh MCP project. This flaw allows remote attackers to manipulate file path arguments, potentially accessing unauthorized files. The project lacks versioning, so specific affected versions are unknown. The vulnerability has a medium severity score of 6.9 and an exploit is publicly available. The project maintainers have not responded to the issue report, and no patch or remediation information is currently available.
CVSS v4.0
Score 6.9medium
Affected software
03-lovepreetSingh
MCP
cpe:2.3:a:03-lovepreetsingh:mcp:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in the create_file function within app/api/mcp/route.ts of the 03-lovepreetSingh MCP project up to commit f95d035c5317fad81af9828286631053ccb23546. It allows remote attackers to perform path traversal by manipulating the filePath or content arguments, potentially leading to unauthorized file access. The project does not use versioning, so affected versions cannot be precisely identified. The issue was reported early to the project but remains unaddressed. An exploit is publicly available, but no evidence of active exploitation in the wild is reported.
Potential Impact
Successful exploitation can lead to unauthorized access to files outside the intended directory, which may expose sensitive information or allow further attacks. The vulnerability is remotely exploitable without authentication, increasing risk. However, no confirmed active exploitation is known at this time.
Mitigation Recommendations
No official fix or patch is currently available. Users should monitor the project for updates or advisories. Until a fix is released, restricting access to the vulnerable functionality or implementing external controls to validate and sanitize file path inputs may reduce risk. Patch status is not yet confirmed — check the vendor advisory or project repository for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-19T21:29:19.931Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab05a5e55bf5e2cf5988bcc
Added to database: 09/20/2026, 22:12:46 UTC
Last enriched: 09/20/2026, 22:13:39 UTC
Last updated: 09/21/2026, 00:11:40 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.