CVE-2026-19038 | MonomythDevelopment la-forge-mcp 1.0.0 screenshot_element Tool src/index.ts screenshotElement output_name path traversal
A vulnerability classified as critical was found in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file src/index.ts of the component screenshot_element Tool. Such manipulation of the argument output_name leads to path traversal.
This vulnerability is documented as CVE-2026-19038. The attack can be executed remotely. Additionally, an exploit exists.
Upgrading the affected component is advised.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.VulDB Recent EntriesRead More