CVE 6.9 MEDIUM

getsimpletool mcpo-simple-server base_manager.py delete_shared_prompt path traversal_CVE-2026-7404

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument detail causes relative path traversal. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Basic Information

ID CVE-2026-7404
Source VulDB
Published Apr 29, 2026 at 20:15

Affected Product

Vendor getsimpletool
Product mcpo-simple-server
Version 0.1
Affected Versions getsimpletool mcpo-simple-server 0.1
getsimpletool mcpo-simple-server 0.2.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.