CVE-2026-19328PoC

LOWCVSS 1.9 · LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal. The attack needs to be performed locally. Upgrading to version 0.1.1 is recommended to address this issue. The identifier of the patch is 855b46739e0f6e8388f17f9d0066ac4298a3965d. Upgrading the affected component is recommended.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-08: 1Mentions · 2026-08-09: 1PoC Mentioned / Linked · 2026-08-08: 1Patch / Workaround · 2026-08-08: 1Technical Details · 2026-08-08: 108-0808-09
Signal classification2 categories
PoC
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-081
PoC1
2026-08-091
General1
Full discourse2 posts
  • CyberSignal | Cybersecurity News@XQOPTRX
    PoC

    🤖 New MCP server path-traversal vulnerability CVE-2026-19328 affects skill-ninja-mcp-server 0.1.0. A flaw involving workspacePath can allow directory traversal in several skill-management functions. A proof-of-concept is publicly available. ✅ Fixed in 0.1.1 🔎 Source: VulDB. #MCP #AISecurity #CVE #CyberSecurity #AppSec

    Post summary

    A path‑traversal flaw (CVE‑2026‑19328) discovered in skill‑ninja‑mcp‑server has a publicly available proof‑of‑concept and is fixed in version 0.1.1.

    0001151
    34 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-19328 A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the f… https://www.cve.org/CVERecord?id=CVE-2026-19328

    Post summary

    The post simply references CVE-2026-19328 with a minimal description of affected functions and a CVE.org link, providing no PoC, exploit, patch, or detailed technical detail.

    000001.1K
    57.9K followersView on X

Explore more