Impact
The flaw is a path traversal vulnerability in NocteDefensor LudusMCP’s insertCredsRangeConfig component. By manipulating the configPath or outputPath arguments, an attacker with local execution privileges can reference arbitrary filesystem locations, potentially exposing sensitive files or corrupting configuration data. The weakness stems from insufficient path validation and is classified as CWE‑22. The vulnerability is confined to local execution, meaning remote attackers must first gain local access to exploit it.
Affected Systems
NocteDefensor LudusMCP versions up to and including 1.0.24 are affected. The product is available as open‑source on GitHub and can be self‑hosted; any deployment running a vulnerable version inherits the path traversal flaw. No patch or fix has been released by the vendor, and the vulnerability remains unaddressed in existing releases.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. No EPSS data is available, suggesting low exploitation probability, and the issue is not listed in the CISA KEV catalog. The attack vector is local, requiring the attacker to be able to execute the component with filesystem privileges. If the component runs with elevated rights, the risk of sensitive data exposure or configuration tampering rises, but the overall threat remains moderate in the absence of known exploitation reports.
OpenCVE Enrichment