Skip to content
Critical Path Traversal Vulnerability in 03-lovepreetSingh MCP

Critical Path Traversal Vulnerability in 03-lovepreetSingh MCP

First seen 21 Sep 2026, 05:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 05:58 UTC
  • CVE-2026-94044 allows remote path traversal exploitation.
  • Affected tool: create_file in 03-lovepreetSingh MCP, commit f95d035.
  • No fixed version available; urgent remediation recommended.

A critical arbitrary file write vulnerability (CWE-22) has been discovered in the create_file tool of 03-lovepreetSingh MCP, affecting commit f95d035c5317fad81af9828286631053ccb23546. The flaw allows attackers to manipulate the filePath and content arguments to perform path traversal, enabling unauthorized file creation or modification. This vulnerability can be exploited remotely without authentication, posing a significant risk to systems using this tool. A proof-of-concept exploit has been demonstrated, confirming the ability to write files outside the intended upload directory. The vulnerability is cataloged as CVE-2026-94044, published on 2026-09-20, and no fixed version is currently available. The project maintainers have not yet responded to the reported issue. Internet-facing deployments of this MCP tool are particularly at risk, especially those lacking proper API security measures.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-20
CVE-2026-94044 published
A critical path traversal vulnerability in 03-lovepreetSingh MCP was officially published.
Redpacketsecurity
2026-09-21
Vulnerability reported
An arbitrary file write vulnerability was identified in the create_file tool of 03-lovepreetSingh MCP.
github.com

More articles in this cluster (3)

Following this threat?

Track CVE-2026-94044 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed