{"data":{"id":"d17e0822-cf11-4018-b0a8-844075d76d40","title":"CVE-2026-44192: A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traver","summary":"A path traversal vulnerability (a flaw that lets attackers access files outside their intended directory) was discovered in the Ansible Lightspeed Model Context Protocol (MCP) server, allowing attackers to manipulate an AI agent through indirect prompt injection (tricking an AI by hiding malicious instructions in its input). This flaw can enable attackers to write files to unauthorized locations on a user's system, potentially exposing sensitive information and allowing them to execute malicious commands that could fully compromise the system.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-44192","publishedAt":"2026-07-22T12:18:00.063Z","cveId":"CVE-2026-44192","cweIds":["CWE-22"],"cvssScore":"6.6","cvssSeverity":"medium","severity":"medium","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Ansible","Ansible Lightspeed","Red Hat"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L","attackVector":"local","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-22T12:18:00.063Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0051"]}}