CVE-2026-19046
Published: Thu, 06 Aug 2026 16:16
Summary
A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component lu
Details
A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name leads to path traversal. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet.
Are YOU affected by CVE-2026-19046?
5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether CVE-2026-19046 (and any other live CVE) applies. Anonymous, no signup.
curl https://mindsparkstack.com/scan.sh | bash
References
- https://github.com/NocteDefensor/LudusMCP/
- https://github.com/NocteDefensor/LudusMCP/issues/4
- https://github.com/gongyanyugyy/public_exp/issues/5
- https://vuldb.com/cve/CVE-2026-19046
- https://vuldb.com/submit/863834
- https://vuldb.com/vuln/386493
- https://vuldb.com/vuln/386493/cti
- https://github.com/gongyanyugyy/public_exp/issues/5
StackPatch runs this match against YOUR installed packages every hour
Free (3 servers) / from $9/mo (14-day free trial) / Solo $9/mo / Pro $29/mo / Team $79/mo. Indie pricing.