CVE-2026-19338

Summary

A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path traversal. The attack must be carried out locally.

Affected Software

VendorProductVersion RangeStatus
automateyournetworkMCPyATS0.1.0affected
automateyournetworkMCPyATS0.1.1affected
automateyournetworkMCPyATS0.1.2affected
automateyournetworkMCPyATS0.1.3affected
automateyournetworkMCPyATS0.1.4affected

Weaknesses

  • CWE-22: Path Traversal

References