MEDIUMVulnerability

CVE-2026-88938

knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply absolute paths or relative traversal sequences to the path argument and retrieve full file contents from outside the intended project directory.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-88938
signal_observed_at
2026-09-18T05:40:02+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-09-10T16:18:12.430
last_modified
2026-09-11T20:19:22.313

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-88938 — Ninja Signal Threat Intelligence | Ninja Signal