Impact
An argument passed as output_path in the upscale_images component of version 0.1.0 can be manipulated to perform a path traversal when the function is invoked. This flaw allows a local user to read or write files outside the intended working directory, potentially exposing or corrupting sensitive data. The vulnerability is a classic path traversal weakness classified under CWE‑22 and its impact is confined to the local machine because no remote execution vector is provided.
Affected Systems
The only affected product is Ichigo3766 image-gen-mcp, specifically the upscale_images module in the 0.1.0 release. No other versions or variants are listed as vulnerable.
Risk and Exploitability
With a CVSS score of 4.8 the flaw receives a medium severity rating. Because the EPSS score is not available and the vulnerability is not in the CISA KEV catalog, the immediate likelihood of widespread exploitation is low. However, the attack requires local privileges, meaning an attacker who gains local access—such as through another vulnerability or physical access—can exploit the path traversal to write or read arbitrary files. Consequently, systems running the unpatched component should treat this as a moderate risk in a local environment.
OpenCVE Enrichment