CVE-2026-7149Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerability affects the function prepare_kaggle_dataset of the file src/kaggle_mcp/server.py. The manipulation of the argument competition_id leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-27); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-27: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-28: 104-2704-28
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7149 Path Traversal in dexhunter kaggle-mcp via Competition ID Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7149

    Post summary

    This post announces a path‑traversal flaw in dexhunter's kaggle‑mcp component that can be triggered via manipulated competition IDs, without providing PoC, exploit details, or patch information.

    0000050
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7149 A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerability affects the function prepare_kaggle_dataset of… https://www.cve.org/CVERecord?id=CVE-2026-7149

    Post summary

    This post announces the discovery of CVE-2026-7149 in the dexhunter kaggle-mcp project, specifying the affected function but providing no further technical or mitigation details.

    0000047
    57.3K followersView on X

Explore more