CVE-2026-19328 | aktsmm skill-ninja-mcp-server 0.1.0 src/installer.ts workspacePath path traversal

SecurityVulns

A vulnerability was found in aktsmm skill-ninja-mcp-server 0.1.0. It has been classified as critical. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal.

This vulnerability is documented as CVE-2026-19328. The attack needs to be performed locally. Additionally, an exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More