Back

MEDIUM

NocteDefensor LudusMCP insert_creds_range_config insertCredsRangeConfig.ts path traversal

Published Aug 9, 2026

Description

A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the component insert_creds_range_config. Executing a manipulation of the argument configPath/outputPath can lead to path traversal. The attack is restricted to local execution. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 9, 2026
Updated Aug 13, 2026
Reserved Aug 9, 2026
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Deferred
Modified Aug 13, 2026
Red Hat
Severity n/a
Public date n/a