CVE Feed

    Dashboard / CVE / CVE-2026-19336

    CVE-2026-19336

    A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal. The attack is only possible with local access. Upgrading to version 2.2.7 is capable of addressing this issue. The patch is named 9c7a7839e690bb4543f0e7481b5740d23808e5fe. It is advisable to upgrade the affected component.

    Published:Aug 9, 2026
    Last Modified:Aug 10, 2026
    EPS:Aug 9, 2026
    EPSS Score:0.00137
    CVSS Score:5.3

    Affected Products

    Vendor
    Pimzino
    Product
    Spec-workflow-mcp

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High