Executive brief
NocteDefensor LudusMCP is a Model Context Protocol server used to manage lab environments through natural language commands. A path traversal vulnerability in the documentation search tool allows a local user to read files outside the intended documentation directory by manipulating the guide_name parameter, potentially exposing sensitive files on the system.
Technical details
The vulnerability is a path traversal flaw in src/tools/ludusEnvironmentGuidesSearch.ts where user-supplied guide_name input is joined directly with the documentation directory using path.join(guidesDir, guideName) and read via fs.readFile() without validation to ensure the resolved path remains within the intended docs directory. An attacker with local access can supply traversal sequences (e.g., "../../../etc/passwd") to escape the guides directory and access arbitrary files readable by the process. The vulnerability affects LudusMCP up to version 1.0.24, and a similar flaw exists in ludusDocsSearch.ts. The fix requires resolving the joined path and verifying it remains within the expected base directory before file access, and rejecting traversal sequences in user-supplied path parameters.
Affected products
- NocteDefensor LudusMCP up to 1.0.24
Timeline
- 2026-08-06: disclosed: CVE-2026-19046 published on NVD
- 2026-04-25: other: Issue reported on GitHub (issue #4) by gongyaugugyy