Description
A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation of the argument filePath/content leads to path traversal. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-20
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Write via Path Traversal
Action: Apply Patch
AI Analysis

Impact

A path‑traversal flaw exists in the create_file handler of a web service where user supplied file paths and content are used to create files on the server. By manipulating the filePath argument an attacker can place files outside the intended directory, potentially overwriting or creating critical system files. The flaw is exploitable from a remote request, and publicly available exploit code indicates that the attack can be deployed directly over the network.

Affected Systems

The affected product is the 03‑lovepreetSingh MCP project. Product releases up to commit f95d035c5317fad81af9828286631053ccb23546 are known to contain the vulnerability. Because the repository contains no proper versioning, the status of later commits is uncertain; any deployment of the pre‑commit code is at risk.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, however the existence of publicly available exploitation scripts and the remote launchability elevate the practical risk. Attackers can send a crafted API request to the create_file endpoint to create or overwrite files on the host filesystem, potentially enabling privilege escalation or persistence if the service runs with elevated permissions.

Generated by OpenCVE AI on September 20, 2026 at 19:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and deploy the latest upstream commit that removes the insecure file handling logic; if a patch is not yet released, remove the create_file endpoint from the public API or restrict its exposure to trusted personnel only.
  • Validate all file path inputs to the create_file handler, rejecting relative paths that contain '..' or absolute paths. Ensure that the target directory for file creation is fixed and cannot be altered by user input.
  • Monitor system logs for anomalous file creation activity and perform regular scans for unauthorized files created by the service.

Generated by OpenCVE AI on September 20, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation of the argument filePath/content leads to path traversal. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Title 03-lovepreetSingh MCP route.ts create_file path traversal
First Time appeared 03-lovepreetsingh
03-lovepreetsingh mcp
Weaknesses CWE-22
CPEs cpe:2.3:a:03-lovepreetsingh:mcp:*:*:*:*:*:*:*:*
Vendors & Products 03-lovepreetsingh
03-lovepreetsingh mcp
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

03-lovepreetsingh Mcp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T14:01:59.953Z

Reserved: 2026-09-19T21:29:19.931Z

Link: CVE-2026-94044

cve-icon Vulnrichment

Updated: 2026-09-21T14:01:33.853Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T19:17:12.960

Modified: 2026-09-21T15:17:37.987

Link: CVE-2026-94044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:02:11Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')