Description
A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name leads to path traversal. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-08-06
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unknown function in src/tools/ludusEnvironmentGuidesSearch.ts of NocteDefensor LudusMCP allows manipulation of the guide_name argument to perform a path traversal attack. The exploitation grants the attacker read or write access to arbitrary files relative to the application’s directory structure. Because the vulnerability requires a locally authenticated user, it can be employed by insiders or by an application running with elevated privileges to compromise confidentiality, integrity, or availability of the file system.

Affected Systems

NocteDefensor LudusMCP versions up to 1.0.24 are affected. The vulnerability is present in the ludus_environment_guides_search component within the ludusEnvironmentGuidesSearch.ts file.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate risk. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited exploitation activity in the wild. The attack vector is local; an attacker must have local system access and the appropriate permissions to leverage the path traversal capability. No public exploit has been documented publicly. The risk is thus confined to environments where local users are able to run the application with sufficient privileges.

Generated by OpenCVE AI on August 6, 2026 at 16:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the installed version of LudusMCP and upgrade to any release newer than 1.0.24 if available.
  • If an upgrade is not possible, restrict local user access to the application’s directory by applying appropriate file system permissions or by running the application in a container or sandbox with limited file access.
  • Review and audit application logs for unexpected attempts to access files outside the intended directories, and consider implementing additional input validation to reject path traversal patterns in the guide_name argument.

Generated by OpenCVE AI on August 6, 2026 at 16:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name leads to path traversal. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet.
Title NocteDefensor LudusMCP ludus_environment_guides_search ludusEnvironmentGuidesSearch.ts path traversal
First Time appeared Noctedefensor
Noctedefensor ludusmcp
Weaknesses CWE-22
CPEs cpe:2.3:a:noctedefensor:ludusmcp:*:*:*:*:*:*:*:*
Vendors & Products Noctedefensor
Noctedefensor ludusmcp
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Noctedefensor Ludusmcp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-06T15:59:13.054Z

Reserved: 2026-08-06T07:34:06.965Z

Link: CVE-2026-19046

cve-icon Vulnrichment

Updated: 2026-08-06T15:56:30.864Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T16:16:41.340

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-19046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:45:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')