CVE 6.9 MEDIUM

ef10007 MLOps_MCP save_file Tool fastmcp_server.py path traversal_CVE-2026-7213

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was detected in ef10007 MLOps_MCP 1.0.0. This impacts an unknown function of the file fastmcp_server.py of the component save_file Tool. The manipulation of the argument filename/destination results in path traversal. The attack may be performed from remote. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Basic Information

ID CVE-2026-7213
Source VulDB
Published Apr 28, 2026 at 01:30

Affected Product

Vendor ef10007
Product MLOps_MCP
Version 1.0.0
Affected Versions ef10007 MLOps_MCP 1.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.