VYPR

spec-workflow-mcp

by Pimzino

CVEs (1)

  • CVE-2026-19336MedAug 9, 2026
    risk 0.27cvss 5.3epss

    A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal. The attack is only possible…