CVE-2026-66004: BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that all
Summary
BlenderMCP before commit 30a3308 has a path traversal vulnerability (a security flaw where attackers can access files outside intended directories) in its download_polyhaven_asset method. Attackers using MITM attacks (interception of network traffic between two parties) or prompt injection (tricking an AI by hiding instructions in its input) can inject malicious file paths like '../../.bashrc' to overwrite sensitive files and gain persistent code execution (the ability to run commands that stay active even after restarting).
Solution / Mitigation
Update BlenderMCP to commit 30a3308 or later, as referenced in the GitHub commit link provided: https://github.com/ahujasid/blender-mcp/commit/30a3308446cd8f81a9446e5a2ed657c0d8d86072
Vulnerability Details
5.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
network
high
none
required
July 24, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-66004
First tracked: July 24, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%