Junglewise Threat Intelligence

CVE-2026-15749: mastergo-design mastergo-magic-mcp path traversal in mcp__C2d tool

CVE-2026-15749 · Severity: medium · CVSS 5.3 · Published 2026-07-14

Technologies: MasterGo Magic-Mcp. Vendors: MasterGo.

Executive brief

A security vulnerability exists in MasterGo Magic MCP, a tool used to connect design software with AI models. An attacker with local access to the system can trick the software into reading sensitive files, such as passwords or private keys, and sending them to external servers. This could lead to the theft of confidential data from the machine where the software is running.

Technical details

A path traversal vulnerability exists in the mcp__C2d component of mastergo-magic-mcp (up to version 0.2.0). The execute function in src/tools/get-c2d.ts accepts a filePath argument which is passed directly to fs.readFileSync without proper validation, sanitization, or scope checking. A local attacker can exploit this by providing a manipulated path (e.g., /etc/passwd or SSH keys), causing the application to read the file and subsequently POST its contents to the MasterGo backend API. While the primary attack vector is local (stdio MCP), it could potentially be exploited via prompt injection in AI agents using the tool. As of the advisory date, the project maintainers have not responded to the issue report.

Affected products

  • mastergo-design mastergo-magic-mcp up to 0.2.0

Timeline

  • 2026-05-29: disclosed: Vulnerability discovered and reported via GitHub issue #88
  • 2026-07-14: advisory: CVE published by VulDB/NVD

References

Related threats