CVE-2026-19046 | NocteDefensor LudusMCP up to 1.0.24 ludus_environment_guides_search ludusEnvironmentGuidesSearch.ts guide_name path traversal

SecurityVulns

A vulnerability categorized as critical has been discovered in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name leads to path traversal.

This vulnerability is uniquely identified as CVE-2026-19046. Local access is required to approach this attack. No exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More