CVE-2026-7213Disclosure

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in ef10007 MLOps_MCP 1.0.0. This impacts an unknown function of the file fastmcp_server.py of the component save_file Tool. The manipulation of the argument filename/destination results in path traversal. The attack may be performed from remote. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Exploit: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-28: 2PoC Mentioned / Linked · 2026-04-28: 1Technical Details · 2026-04-28: 104-28
Signal classification2 categories
Disclosure
150.0%
Exploit
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7213 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7213 #CVE-2026-7213 #CVE #High #CyberSecurity #InfoSec https://t.co/5EVCg8hCLu

    Post summary

    Tweet announces a new CVE (CVE-2026-7213) with a severity of 7.3 and high risk, but provides no further technical or remediation details.

    0000043
    142 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Exploit

    CVE-2026-7213 Path Traversal in ef10007 MLOps_MCP 1.0.0 save_file Tool (Public Exploit) https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7213

    Post summary

    CVE-2026-7213 is a public path‑traversal vulnerability in the ef10007 MLOps_MCP 1.0.0 save_file tool, with a publicly disclosed exploit but no patch or detailed exploitation guide mention.

    0000045
    4.0K followersView on X

Explore more