CVE-2026-15528

Severity CVSS v4.0:
LOW
Type:
CWE-693 Protection Mechanism Failure
Publication date:
13/07/2026
Last modified:
13/07/2026

Description

A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file kicad_mcp/utils/path_validator.py. Performing a manipulation of the argument project_path/schematic_path results in protection mechanism failure. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.