lowCVSS 6.3Vulnerability

CVE-2026-7738

A security flaw has been discovered in puchunjie doc-tools-mcp 1.0.18. This affects the function create_document/open_document of the file src/mcp-server.ts of the component MCP Interface. The manipulation of the argument filePath results in path traversal. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Properties

severity
low
summary
@puchunjie/doc-tools-mcp has a Path Traversal Issue
epss_score
0.00288
cvss_score
6.3
ghsa_published
2026-05-04T09:31:09Z
source_url
https://github.com/advisories/GHSA-gcmm-c94j-j47x
ghsa_updated
2026-05-08T16:54:56Z
ghsa_id
GHSA-gcmm-c94j-j47x
cve_id
CVE-2026-7738
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
epss_percentile
0.21649

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]npm/@puchunjie/doc-tools-mcp

AFFECTS (1)

[Software]npm/@puchunjie/doc-tools-mcp

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-7738 (CVSS 6.3) — Ninja Signal Threat Intelligence | Ninja Signal