Junglewise Threat Intelligence

CVE-2026-19323: azer react-analyzer-mcp path traversal in analyze-project

CVE-2026-19323 · Severity: medium · CVSS 5.3 · Published 2026-08-09

Executive brief

react-analyzer-mcp is an MCP server tool that analyzes and generates documentation for React component files locally. A path traversal vulnerability in the analyze-project function allows a malicious local user to read arbitrary .jsx/.tsx files outside the intended project folder by manipulating the projectName parameter, potentially exposing sensitive application source code.

Technical details

The vulnerability is a path traversal flaw in the generateProjectDocs function (src/index.ts) of the analyze-project component. The projectName parameter is used directly in path.join(PROJECT_ROOT, subFolder) without validation or canonicalization, allowing attackers to inject traversal sequences (e.g., "../") to escape the PROJECT_ROOT boundary. The vulnerable code then recursively scans the constructed directory and reads .jsx/.tsx files via fs.readFileSync. Attack requires local access and MCP client control. An attacker can enumerate and read arbitrary React source files on the host system. No patch has been released; the project uses rolling releases and has not responded to early disclosure.

Affected products

  • azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0

Timeline

  • 2026-04-26: disclosed: Issue reported on GitHub
  • 2026-08-09: advisory: CVE-2026-19323 published
  • 2026-04-26: other: Project informed early but has not responded

References