CVE-2026-19046

Severity CVSS v4.0:
MEDIUM
Type:
CWE-22 Path Traversal
Publication date:
06/08/2026
Last modified:
12/08/2026

Description

A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name leads to path traversal. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet.