CVE-2026-19038

Source
https://cve.org/CVERecord?id=CVE-2026-19038
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19038.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19038
Published
2026-08-06T12:45:10.595Z
Modified
2026-08-08T03:48:18.203827052Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
MonomythDevelopment la-forge-mcp screenshot_element Tool index.ts screenshotElement path traversal
Details

A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file src/index.ts of the component screenshotelement Tool. Such manipulation of the argument outputname leads to path traversal. The attack can be executed remotely. Upgrading to version 1.1.1 is capable of addressing this issue. The name of the patch is 1102172c9adec4a619e241efd6bfb74f5b1f4332. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19038.json",
    "cna_assigner": "VulDB",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.0.0"
                },
                {
                    "last_affected": "1.0.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/monomythdevelopment/la-forge-mcp

Affected ranges

Type
GIT
Repo
https://github.com/monomythdevelopment/la-forge-mcp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19038.json"