CVE-2026-19336
A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the fi
CVSS
5.3
Medium
EPSS
0.1%
p3
KEV
—
Exploit Today
1
0-100
Published: Aug 9, 2026 · Last modified: Aug 12, 2026 · CWE-22
0.1%EPSS · 30 days0.1%
2026-08-092026-08-31
A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal. The attack is only possible with local access. Upgrading to version 2.2.7 is capable of addressing this issue. The patch is named 9c7a7839e690bb4543f0e7481b5740d23808e5fe. It is advisable to upgrade the affected component.
- github.comhttps://github.com/Pimzino/spec-workflow-mcp/
- github.comhttps://github.com/Pimzino/spec-workflow-mcp/commit/9c7a7839e690bb4543f0e7481b5740d23808e5fe
- github.comhttps://github.com/Pimzino/spec-workflow-mcp/issues/220
- github.comhttps://github.com/Pimzino/spec-workflow-mcp/pull/222
- vuldb.comhttps://vuldb.com/cve/CVE-2026-19336
- vuldb.comhttps://vuldb.com/submit/865260
- vuldb.comhttps://vuldb.com/vuln/387172
- vuldb.comhttps://vuldb.com/vuln/387172/cti
- github.comhttps://github.com/Pimzino/spec-workflow-mcp/issues/220
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-786579.8 CRI—
———The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The malicious path traversal URL is submitted via form upload field and stored in the database, with deletion triggered when an administrator deletes the submission record from the admin panel.6hCVE-2026-844424.4 MED—
———A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component com.mapquest.android.ace. The manipulation leads to path traversal. An attack has to be approached locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.9hCVE-2026-844417.3 HIG—
———A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of the file i.php of the component Image Derivative Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.9hCVE-2026-149828.1 HIG—
———The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The two-stage exploit requires a first request to the file.save task to persist the path-traversal string into file metadata, followed by a second request to the file.delete task to trigger the unlink call — both endpoints lack capability checks and nonce enforcement.9hCVE-2026-844314.4 MED—
———A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of the argument _display_name results in path traversal. The attack requires a local approach. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.10hCVE-2026-847027.5 HIG—
———facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at arbitrary locations.11h