Vulnerability Description
A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the argument sessionCommand/sessionPath causes path traversal. The attack requires local access. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/bartekke8it56w2/new-mcp/
- https://github.com/bartekke8it56w2/new-mcp/issues/10
- https://vuldb.com/cve/CVE-2026-19370
- https://vuldb.com/submit/866268
- https://vuldb.com/vuln/387254
- https://vuldb.com/vuln/387254/cti
FAQ
What is CVE-2026-19370?
CVE-2026-19370 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This man...
How severe is CVE-2026-19370?
CVE-2026-19370 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-19370?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.