Impact
The mastergo-design mastergo-magic-mcp component mcp__getComponentGenerator contains a path traversal flaw in the execute function of component-workflow.md. Manipulation of the rootPath argument can cause the application to traverse directories outside the intended location, potentially allowing an attacker to read or list files on the underlying file system. This vulnerability is limited to the local execution context and does not provide direct network exposure. The same weakness is identified by CWE-22.
Affected Systems
The affected product is mastergo-design mastergo-magic-mcp, specifically all releases up to and including version 0.2.0. No fixed version is indicated in the advisory; users should verify whether newer releases have been published since the vulnerability was disclosed.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact. The EPSS score of less than 1 % shows a very low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The attack can only be carried out locally, so the risk is further confined to environments where a user can run the application or has local file write access.
OpenCVE Enrichment