CVE-2026-19338

Severity CVSS v4.0:
LOW
Type:
CWE-22 Path Traversal
Publication date:
09/08/2026
Last modified:
09/08/2026

Description

A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path traversal. The attack must be carried out locally.