Impact
The vulnerability resides in the Journey/Usage component of Hulupeep mcp-ui-probe, where the journeyId/filename argument of the get_journey/delete_journey/analyze_journey/usage_stats functions is not properly validated. An attacker with local access can manipulate this argument to traverse the filesystem hierarchy and read arbitrary files present on the host. This flaw does not provide remote code execution but enables local disclosure of sensitive data through file reads.
Affected Systems
The flaw affects Hulupeep mcp-ui-probe versions up to 0.2.0. Any deployment of this product within that version range is vulnerable. The vulnerability is specific to the JourneyStorage.ts module in the Journey/Usage path of the codebase.
Risk and Exploitability
The CVSS score for this flaw is 4.8, indicating moderate severity. Because the attack vector is local, exploitation requires the attacker to already have some level of access or privilege on the affected system; it is not exploitable from the network. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Nonetheless, local compromise can lead to confidentiality breaches of arbitrary files, so the risk is non‑negligible for systems where the vulnerable component is exposed to untrusted local users.
OpenCVE Enrichment