mediumCVSS 6.5Vulnerability
CVE-2026-7645
A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciousness-explorer/mcp/server.js of the component MCP Interface. The manipulation results in path traversal. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Properties
- severity
- medium
- summary
- sublinear-time-solver has a Path Traversal Issue
- epss_score
- 0.00462
- cvss_score
- 6.5
- ghsa_published
- 2026-05-02T18:30:27Z
- source_url
- https://github.com/advisories/GHSA-gc2j-wpjv-jhrw
- ghsa_updated
- 2026-05-07T21:09:00Z
- ghsa_id
- GHSA-gc2j-wpjv-jhrw
- cve_id
- CVE-2026-7645
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- signal_observed_at
- 2026-09-11T17:55:57+00:00
- is_ghsa_only
- false
- epss_percentile
- 0.39328
Related Entities (5)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]npm/sublinear-time-solver
AFFECTS (1)
→[Software]npm/sublinear-time-solver
Explore deeper with Ninja Signal's threat intelligence graph