Impact
The vulnerability resides in the HistoryService component of abrinsmead MindPilot MCP. By manipulating the argument ID, an attacker can trigger a path traversal that allows access to files outside the intended directory. This flaw is a CWE‑22 weakness and permits an attacker who can run code locally to read or potentially modify sensitive files, compromising the confidentiality and integrity of the system. The exploit requires local access; no known remote attack vector exists and the EPSS score is unavailable. The CVSS score of 4.8 indicates moderate severity for users with local privileges.
Affected Systems
abrinsmead MindPilot MCP version 0.5.0 is affected. The vulnerability is tied to the HistoryService module of this release.
Risk and Exploitability
Because the flaw is limited to local execution, the risk is confined to systems where an attacker can gain local access. The moderate CVSS score reflects the impact of potential data disclosure or modification if successful. The vulnerability is not listed in CISA KEV, and no public exploit is known. Nonetheless, an attacker who can obtain local control could leverage this path traversal to read privileged files or undermine system integrity. Strong local access controls are therefore recommended to reduce exploitation likelihood.
OpenCVE Enrichment