Impact
The vulnerability in dekdee's adobe-xd-mcp allows an attacker to manipulate the outputFile/outputDir parameters within the file-access-from-request endpoint to perform a path traversal attack, potentially enabling the reading or writing of arbitrary files on the host system.
Affected Systems
dekdee:adobe-xd-mcp version 1.0.0 is affected. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but publicly disclosed exploits exist, meaning the risk is tangible and attackers can launch the attack remotely via the exposed endpoint.
OpenCVE Enrichment