mediumCVSS 6.5Vulnerability

CVE-2026-7645

A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciousness-explorer/mcp/server.js of the component MCP Interface. The manipulation results in path traversal. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Properties

severity
medium
summary
sublinear-time-solver has a Path Traversal Issue
epss_score
0.00462
cvss_score
6.5
ghsa_published
2026-05-02T18:30:27Z
source_url
https://github.com/advisories/GHSA-gc2j-wpjv-jhrw
ghsa_updated
2026-05-07T21:09:00Z
ghsa_id
GHSA-gc2j-wpjv-jhrw
cve_id
CVE-2026-7645
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
epss_percentile
0.39328

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/sublinear-time-solver

AFFECTS (1)

[Software]npm/sublinear-time-solver

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-7645 (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal