Impact
The Markdownify.mcp component contains a flaw in its saveToTempFile function where temporary file names are generated with insufficient randomness as identified by CWE-310 and CWE-330 weaknesses. The issue means a local user with execution privileges inside the application can potentially predict or enumerate the temporary file paths that will be created. Based on the description, it is inferred that this could allow a race condition or overwrite of existing files, but the flaw does not provide a path to remote code execution or broader system compromise.
Affected Systems
The vulnerability applies to the zcaceres markdownify‑mcp project, specifically its webpage‑to‑markdown, youtube‑to‑markdown, and bing‑search‑to‑markdown modules. All releases up to and including version 1.1.0 are affected.
Risk and Exploitability
The CVSS score of 2.0 indicates low severity, and the EPSS score of less than 1 percent reflects a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local execution with a high degree of complexity and is considered difficult; however, an exploit has been published and may be used. Since the vendor fix has not yet been released, the overall risk to organizations remains low and is confined to local environments that run the vulnerable component.
OpenCVE Enrichment