{"id":"CVE-2026-19270","summary":"Hulupeep mcp-ui-probe Journey/Usage JourneyStorage.ts usage_stats path traversal","details":"A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey/analyze_journey/usage_stats of the file src/journey/JourneyStorage.ts of the component Journey/Usage. The manipulation of the argument journeyId/filename results in path traversal. The attack requires a local approach. The project was informed of the problem early through an issue report but has not responded yet.","modified":"2026-08-12T03:51:37.146703429Z","published":"2026-08-08T07:45:11.576Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19270.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0.1"},{"last_affected":"0.1"}]}],"cna_assigner":"VulDB","cwe_ids":["CWE-22"]},"references":[{"type":"WEB","url":"https://github.com/Hulupeep/mcp-ui-probe/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19270.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19270"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-19270"},{"type":"ADVISORY","url":"https://vuldb.com/submit/865223"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/387013"},{"type":"REPORT","url":"https://github.com/Hulupeep/mcp-ui-probe/issues/1"},{"type":"REPORT","url":"https://vuldb.com/vuln/387013/cti"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hulupeep/mcp-ui-probe","events":[{"introduced":"0214277fabdd8d4f8697ddd29f25a60eab1261c6"},{"last_affected":"0214277fabdd8d4f8697ddd29f25a60eab1261c6"}],"database_specific":{"extracted_events":[{"introduced":"0.2.0"},{"last_affected":"0.2.0"}],"source":"AFFECTED_FIELD"}}],"versions":["0.2.0","v0.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19270.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}