๐Ÿ” CVE Alert

CVE-2026-19336

MEDIUM 5.3

Pimzino spec-workflow-mcp approvals.ts ApprovalStorage.createApproval path traversal

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal. The attack is only possible with local access. Upgrading to version 2.2.7 is capable of addressing this issue. The patch is named 9c7a7839e690bb4543f0e7481b5740d23808e5fe. It is advisable to upgrade the affected component.

CWE CWE-22
Vendor pimzino
Product spec-workflow-mcp
Published Aug 9, 2026
Stay Ahead of the Next One

Get instant alerts for pimzino spec-workflow-mcp

Be the first to know when new medium vulnerabilities affecting pimzino spec-workflow-mcp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Pimzino / spec-workflow-mcp
2.2.0 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5 2.2.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/387172 vuldb.com: https://vuldb.com/vuln/387172/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19336 vuldb.com: https://vuldb.com/submit/865260 github.com: https://github.com/Pimzino/spec-workflow-mcp/issues/220 github.com: https://github.com/Pimzino/spec-workflow-mcp/pull/222 github.com: https://github.com/Pimzino/spec-workflow-mcp/commit/9c7a7839e690bb4543f0e7481b5740d23808e5fe github.com: https://github.com/Pimzino/spec-workflow-mcp/

Credits

๐Ÿ” gongyanyu04 (VulDB User)