Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 09 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component upload_document. Performing a manipulation of the argument File results in path traversal. Attacking locally is a requirement. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | Handwriting-OCR handwriting-ocr-mcp-server upload_document index.ts fs.readFileSync path traversal | |
| First Time appeared |
Handwriting-ocr
Handwriting-ocr handwriting-ocr-mcp-server |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:handwriting-ocr:handwriting-ocr-mcp-server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Handwriting-ocr
Handwriting-ocr handwriting-ocr-mcp-server |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-09T22:30:10.705Z
Reserved: 2026-08-09T07:25:11.045Z
Link: CVE-2026-19372
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-09T23:30:06Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')