Impact
A flaw in lamaalrajih kicad‑mcp’s path_validator.py processes project_path and schematic_path arguments erroneously, which causes the protection mechanism that is meant to guard against path misuse to fail. This failure exploits CWE‑693: Improper Check or Handling of a Critical Security Operation, and enables a local user to craft a path that bypasses the intended safeguards, potentially allowing operations on files outside the designated directories. Inferred from the description, this bypass could provide local privilege escalation by permitting unauthorized file modifications or other elevated actions. The flaw is limited to the local environment and no remote exploitation path is documented.
Affected Systems
The lamaalrajih kicad‑mcp up to and including version 3.3.1 has this vulnerability. No fixed version has been published; users of earlier releases should review the project’s repository for any updates that address the path_validator issue.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because local access is required, but any user with local login privileges could potentially exploit the failure to gain additional access or execute unwanted operations.
OpenCVE Enrichment