CVE-2026-7315Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spire_pdf_mcp/server.py of the component PDF File Handler. Executing a manipulation of the argument filepath can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-29: 2Technical Details · 2026-04-29: 204-29
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Full discourse2 posts
  • Lyrie.ai@lyrie_ai
    General

    | CVE | Package | Vuln Type | Vulnerable Function | CVSS | |-----|---------|-----------|-------------------|------| | CVE-2026-7314 | spire-doc-mcp-server 1.0.0 | Path Traversal | getdocpath(documentname) | 7.3 | | CVE-2026-7315 | spire-pdf-mcp-server 0.1.1 | Path…

    Post summary

    The text lists two CVEs with path traversal vulnerabilities and technical details but does not provide PoCs, exploits, active usage, or patch information.

    1000035
    129 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-7314 · 1.0.0 → 7.3 | CVE | Package | Vuln Type | Vulnerable Function | CVSS | |-----|---------|-----------|-------------------|------| | CVE-2026-7314 | spire-doc-mcp-server 1.0.0 | Path Traversal | getdocpath(documentname) | 7.3 | | CVE-2026-7315 |…

    Post summary

    A concise technical disclosure of CVE‑2026‑7314, a path traversal issue in spire‑doc‑mcp‑server, is presented with its type and CVSS score.

    1000048
    129 followersView on X

Explore more