lowCVSS 6.3Vulnerability
CVE-2026-7738
A security flaw has been discovered in puchunjie doc-tools-mcp 1.0.18. This affects the function create_document/open_document of the file src/mcp-server.ts of the component MCP Interface. The manipulation of the argument filePath results in path traversal. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Properties
- severity
- low
- summary
- @puchunjie/doc-tools-mcp has a Path Traversal Issue
- epss_score
- 0.00288
- cvss_score
- 6.3
- ghsa_published
- 2026-05-04T09:31:09Z
- source_url
- https://github.com/advisories/GHSA-gcmm-c94j-j47x
- ghsa_updated
- 2026-05-08T16:54:56Z
- ghsa_id
- GHSA-gcmm-c94j-j47x
- cve_id
- CVE-2026-7738
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- signal_observed_at
- 2026-09-11T17:55:57+00:00
- is_ghsa_only
- false
- epss_percentile
- 0.21649
Related Entities (5)
ENRICHED_BY (1)
→[Source]FIRST EPSS
VULNERABLE_TO (1)
←[Software]npm/@puchunjie/doc-tools-mcp
AFFECTS (1)
→[Software]npm/@puchunjie/doc-tools-mcp
HAS_WEAKNESS (1)
→[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph