Medium severity5.3NVD Advisory· Published Aug 9, 2026
CVE-2026-19328
CVE-2026-19328
Description
A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal. The attack needs to be performed locally. Upgrading to version 0.1.1 is recommended to address this issue. The identifier of the patch is 855b46739e0f6e8388f17f9d0066ac4298a3965d. Upgrading the affected component is recommended.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <0.1.1
Patches
Vulnerability mechanics
References
7- github.com/aktsmm/skill-ninja-mcp-server/commit/855b46739e0f6e8388f17f9d0066ac4298a3965dnvd
- github.com/aktsmm/skill-ninja-mcp-server/issues/2nvd
- github.com/aktsmm/skill-ninja-mcp-server/releases/tag/v0.1.1nvd
- vuldb.com/cve/CVE-2026-19328nvd
- vuldb.com/submit/865245nvd
- vuldb.com/vuln/387162nvd
- vuldb.com/vuln/387162/ctinvd
News mentions
0No linked articles in our index yet.