CVE-2026-19328

Source
https://cve.org/CVERecord?id=CVE-2026-19328
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19328.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19328
Published
2026-08-09T02:45:10.898Z
Modified
2026-08-14T03:51:33.966490271Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
aktsmm skill-ninja-mcp-server installer.ts uninstallSkill path traversal
Details

A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal. The attack needs to be performed locally. Upgrading to version 0.1.1 is recommended to address this issue. The identifier of the patch is 855b46739e0f6e8388f17f9d0066ac4298a3965d. Upgrading the affected component is recommended.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "0.1.0"
                },
                {
                    "last_affected": "0.1.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19328.json"
}
References

Affected packages

Git / github.com/aktsmm/skill-ninja-mcp-server

Affected ranges

Type
GIT
Repo
https://github.com/aktsmm/skill-ninja-mcp-server
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19328.json"