Executive brief
Rive MCP Server is an open-source bridge connecting AI assistants to Rive interactive animations. The importRiveFile feature lacks validation on user-supplied library identifiers, allowing an attacker to write arbitrary files outside the intended storage directory. An attacker with local access to invoke MCP tools can overwrite configuration files or inject malicious content into the system.
Technical details
The vulnerability is a path traversal flaw in the importRiveFile flow (packages/mcp-server/src/tools/importRiveFile.ts and packages/mcp-server/src/utils/storage.ts). The libraryId parameter is taken directly from user input and concatenated into a file path via path.join(config.manifestsPath, `${library.id}.library.json`) without post-join validation. An attacker can supply traversal sequences such as `../../` to escape the manifests directory and write files to arbitrary locations subject to process permissions. The attack requires local access to invoke the MCP tool. No patch has been released; the project maintainer was notified but has not yet responded.
Affected products
- astralisone Rive MCP Server Core up to db1d0cc4cd52589116360428b7504fd0ca748b3e
Timeline
- 2026-04-27: disclosed: Issue #2 opened on GitHub by gongyaugugyy
- 2026-08-08: advisory: CVE-2026-19288 published to NVD