CVE-2026-9467: Path Traversal in debugmcp mcp-debugger
CVE-2026-9467 is a path traversal vulnerability in the debugmcp mcp-debugger product up to version 0.20.0. It affects the handleGetSourceContext function in the src/server.ts file. This vulnerability can be exploited remotely without user interaction and requires low privileges. The exploit code is publicly available, and the vendor has not responded to disclosure attempts. The vulnerability has a medium severity with a CVSS score of 5.3. No official patch or remediation guidance is currently available.
AI Analysis
Technical Summary
The vulnerability CVE-2026-9467 exists in debugmcp mcp-debugger versions up to 0.20.0, specifically in the handleGetSourceContext function within src/server.ts. It allows an attacker to perform a path traversal attack remotely, potentially accessing files outside the intended directory scope. The attack requires low privileges and no user interaction, with low complexity. The vendor was contacted but did not provide any response or patch. Public exploit code is available, increasing the risk of exploitation.
Potential Impact
Successful exploitation of this vulnerability allows an attacker to traverse the file system paths remotely, potentially accessing sensitive files that should be restricted. This could lead to unauthorized information disclosure. The CVSS score of 5.3 reflects a medium severity impact with limited scope and no privilege escalation or integrity/availability impact indicated.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded and no official patch or workaround is available, users should consider restricting network access to the vulnerable service and monitor for exploitation attempts. Avoid exposing the mcp-debugger service to untrusted networks until a fix is released.
CVE-2026-9467: Path Traversal in debugmcp mcp-debugger
Description
CVE-2026-9467 is a path traversal vulnerability in the debugmcp mcp-debugger product up to version 0.20.0. It affects the handleGetSourceContext function in the src/server.ts file. This vulnerability can be exploited remotely without user interaction and requires low privileges. The exploit code is publicly available, and the vendor has not responded to disclosure attempts. The vulnerability has a medium severity with a CVSS score of 5.3. No official patch or remediation guidance is currently available.
CVSS v4.0
Score 5.3medium
Affected software
pkg:npm/debugmcp/mcp-debuggerRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-9467 exists in debugmcp mcp-debugger versions up to 0.20.0, specifically in the handleGetSourceContext function within src/server.ts. It allows an attacker to perform a path traversal attack remotely, potentially accessing files outside the intended directory scope. The attack requires low privileges and no user interaction, with low complexity. The vendor was contacted but did not provide any response or patch. Public exploit code is available, increasing the risk of exploitation.
Potential Impact
Successful exploitation of this vulnerability allows an attacker to traverse the file system paths remotely, potentially accessing sensitive files that should be restricted. This could lead to unauthorized information disclosure. The CVSS score of 5.3 reflects a medium severity impact with limited scope and no privilege escalation or integrity/availability impact indicated.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded and no official patch or workaround is available, users should consider restricting network access to the vulnerable service and monitor for exploitation attempts. Avoid exposing the mcp-debugger service to untrusted networks until a fix is released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-05-24T08:58:22.240Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a146d50a5ae1af1aabec1c6
Added to database: 05/25/2026, 15:40:00 UTC
Last enriched: 06/01/2026, 21:01:51 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 106
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.