Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 08 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey/analyze_journey/usage_stats of the file src/journey/JourneyStorage.ts of the component Journey/Usage. The manipulation of the argument journeyId/filename results in path traversal. The attack requires a local approach. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | Hulupeep mcp-ui-probe Journey/Usage JourneyStorage.ts usage_stats path traversal | |
| First Time appeared |
Hulupeep
Hulupeep mcp-ui-probe |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:hulupeep:mcp-ui-probe:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hulupeep
Hulupeep mcp-ui-probe |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-08T07:45:11.576Z
Reserved: 2026-08-07T14:16:23.931Z
Link: CVE-2026-19270
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-08T10:00:04Z