GHSA-6j8j-xrrf-px36MediumCVSS 3.3
A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted...
🔗 CVE IDs covered (1)
📋 Description
A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name leads to path traversal. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-19046
- https://github.com/NocteDefensor/LudusMCP/issues/4
- https://github.com/gongyanyugyy/public_exp/issues/5
- https://github.com/NocteDefensor/LudusMCP
- https://vuldb.com/cve/CVE-2026-19046
- https://vuldb.com/submit/863834
- https://vuldb.com/vuln/386493
- https://vuldb.com/vuln/386493/cti
- https://github.com/advisories/GHSA-6j8j-xrrf-px36