{"data":{"id":"9fd3b134-dd42-41b4-afdc-30890eeebeea","title":"CVE-2026-66004: BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that all","summary":"BlenderMCP before commit 30a3308 has a path traversal vulnerability (a security flaw where attackers can access files outside intended directories) in its download_polyhaven_asset method. Attackers using MITM attacks (interception of network traffic between two parties) or prompt injection (tricking an AI by hiding instructions in its input) can inject malicious file paths like '../../.bashrc' to overwrite sensitive files and gain persistent code execution (the ability to run commands that stay active even after restarting).","solution":"Update BlenderMCP to commit 30a3308 or later, as referenced in the GitHub commit link provided: https://github.com/ahujasid/blender-mcp/commit/30a3308446cd8f81a9446e5a2ed657c0d8d86072","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-66004","publishedAt":"2026-07-24T15:19:07.050Z","cveId":"CVE-2026-66004","cweIds":["CWE-22"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["BlenderMCP"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-24T15:19:07.050Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]}}