CVE-2026-7319General

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in elinsky execution-system-mcp 0.1.0. The impacted element is the function _get_context_file_path of the file src/execution_system_mcp/server.py of the component add_action Tool. This manipulation of the argument context causes path traversal. The attack can be initiated remotely. The exploit has been published and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-29: 2Technical Details · 2026-04-29: 104-29
Signal classification1 categories
General
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-7319 carries a — because in an execution system, path traversal isn't just file read. It's RCE. | CVE | Package | Vuln Type | Vulnerable Function | CVSS | |-----|---------|-----------|-------------------|------| | CVE-2026-7314 | spire-doc-mcp-server 1.0.0 | Path…

    Post summary

    The snippet identifies CVE-2026-7319 as a path traversal vulnerability leading to remote code execution but offers no proof‑of‑concept, exploit tool, active exploitation evidence, patch details, or debunking claim.

    1000033
    129 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7319 Path Traversal in Elinsky Execution-System-MCP 0.1.0 Add_Action Tool https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7319

    Post summary

    The post announces CVE‑2026‑7319 as a path traversal vulnerability in Elinsky Execution‑System‑MCP 0.1.0 Add_Action Tool but offers no further detail or actionable information.

    0000047
    4.0K followersView on X

Explore more