CVE-2026-81491 | boxpositron with-context-mcp up to 3.0.7 src/index.ts path traversal
A vulnerability was found in boxpositron with-context-mcp up to 3.0.7 and classified as critical. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal.
This vulnerability is registered as CVE-2026-81491. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More