Impact
The bug resides in the installer module of the skill‑ninja‑mcp‑server. By supplying a maliciously crafted workspacePath argument, an attacker can cause the application to read or write files outside the intended directory. The flaw can lead to unauthorized access to system files or modification of sensitive configuration files. The weakness is a classic path traversal (CWE‑22) and is limited to local execution; it cannot be triggered remotely over the network.
Affected Systems
Products affected are aktsmm skill‑ninja‑mcp‑server version 0.1.0. The fix is available in 0.1.1, which includes the patch with commit identifier 855b46739e0f6e8388f17f9d0066ac4298a3965d.
Risk and Exploitability
The CVSS score of 4.8 places the issue in the medium severity range. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Because the exploit requires local access, the likelihood of successful exploitation in most environments is low, but any system running the vulnerable version with local user privileges is at risk.
OpenCVE Enrichment