CVE-2026-19370 | bartekke8it56w2 new-mcp 0.1.0 geminithinking index.ts fs.writeFileSync/fs.existsSync/fs.readFileSync sessionCommand/sessionPath path traversal
A vulnerability classified as critical has been found in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the argument sessionCommand/sessionPath causes path traversal.
This vulnerability appears as CVE-2026-19370. The attack requires local access. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More