GHSA-gc2j-wpjv-jhrw

Suggest an improvement
Source
https://github.com/advisories/GHSA-gc2j-wpjv-jhrw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-gc2j-wpjv-jhrw/GHSA-gc2j-wpjv-jhrw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gc2j-wpjv-jhrw
Aliases
  • CVE-2026-7645
Published
2026-05-02T18:30:27Z
Modified
2026-05-07T21:26:25Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
sublinear-time-solver has a Path Traversal Issue
Details

A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciousness-explorer/mcp/server.js of the component MCP Interface. The manipulation results in path traversal. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-07T21:08:58Z",
    "nvd_published_at": "2026-05-02T16:16:15Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / sublinear-time-solver

Package

Name
sublinear-time-solver
View open source insights on deps.dev
Purl
pkg:npm/sublinear-time-solver

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.5.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-gc2j-wpjv-jhrw/GHSA-gc2j-wpjv-jhrw.json"