CVE-2026-81485 | danielpopamd linkedin-ads-mcp 1.0.0 Media Upload campaign-management.ts fs.readFileSync filePath path traversal

SecurityVulns

A vulnerability, which was classified as problematic, was found in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the component Media Upload. Such manipulation of the argument filePath leads to path traversal.

This vulnerability is listed as CVE-2026-81485. The attack may be performed from remote. In addition, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More