CVE-2026-7314Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py. Performing a manipulation of the argument document_name results in path traversal. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-29); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-29: 3Mentions · 2026-05-01: 1Technical Details · 2026-04-29: 3Technical Details · 2026-05-01: 104-2905-01
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-293
Disclosure1General2
2026-05-011
Disclosure1
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    General

    | CVE | Package | Vuln Type | Vulnerable Function | CVSS | |-----|---------|-----------|-------------------|------| | CVE-2026-7314 | spire-doc-mcp-server 1.0.0 | Path Traversal | getdocpath(documentname) | 7.3 | | CVE-2026-7315 | spire-pdf-mcp-server 0.1.1 | Path…

    Post summary

    The snippet lists two Path Traversal vulnerabilities (CVE-2026-7314 and CVE-2026-7315) with basic details such as function names and CVSS scores, but provides no PoC, exploit, patch, or exploitation evidence.

    1000035
    129 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-7319 carries a — because in an execution system, path traversal isn't just file read. It's RCE. | CVE | Package | Vuln Type | Vulnerable Function | CVSS | |-----|---------|-----------|-------------------|------| | CVE-2026-7314 | spire-doc-mcp-server 1.0.0 | Path…

    Post summary

    The snippet identifies CVE-2026-7319 as a path traversal vulnerability leading to RCE, but it offers no evidence of active exploitation, PoC, or patch information.

    1000033
    129 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-7314 · 1.0.0 → 7.3 | CVE | Package | Vuln Type | Vulnerable Function | CVSS | |-----|---------|-----------|-------------------|------| | CVE-2026-7314 | spire-doc-mcp-server 1.0.0 | Path Traversal | getdocpath(documentname) | 7.3 | | CVE-2026-7315 |…

    Post summary

    The snippet provides a basic disclosure of CVE‑2026‑7314, indicating a path traversal flaw in spire‑doc‑mcp‑server 1.0.0 with a CVSS score of 7.3, but offers no proof of concept, exploit code, or patch information.

    1000048
    129 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7314 Path Traversal in eiceblue Spire-Doc-MCP-Server 1.0.0 via Document Name Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7314

    Post summary

    The content introduces CVE-2026-7314, detailing a path traversal flaw in eiceblue Spire-Doc-MCP-Server 1.0.0 accessed through document name manipulation, with no PoC, exploit, or patch information provided.

    0000047
    4.0K followersView on X

Explore more