CVE-2026-19370: A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSyn
mediumvulnerability
security
Summary
A vulnerability (CVE-2026-19370) was found in the new-mcp software version 0.1.0 that allows path traversal (manipulating file paths to access files outside intended directories) through functions like fs.writeFileSync and fs.readFileSync in the geminithinking component. The attack requires someone with local access to the system, and the project developer has been notified but has not yet responded.
Vulnerability Details
CVSS Score
5.3(medium)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Vector
local
Attack Complexity
low
Privileges Required
low
User Interaction
none
Disclosure Date
August 9, 2026
Classification
Attack SophisticationTrivial
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19370
First tracked: August 9, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 95%