Impact
A path‑traversal flaw exists in the ApprovalStorage.createApproval function of Pimzino spec-workflow-mcp when the categoryName argument is manipulated. The vulnerability allows a local user to cause the application to reference arbitrary file system paths, potentially enabling reading or writing of files outside the intended directory.
Affected Systems
Pimzino spec-workflow-mcp versions up to 2.2.6 are affected. Version 2.2.7 contains the fix that prevents the path traversal by validating the categoryName input.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The EPSS value is not provided and the issue is not listed in the CISA KEV catalog. The attack requires local access, meaning an attacker must already have some level of privilege on the host to exploit the flaw. Once local access is achieved, the path traversal could be used to reach arbitrary files on the system, impacting confidentiality and integrity of the file system.
OpenCVE Enrichment