A weakness has been identified in zcaceres markdownify-mcp up to 1.1.0. The affected element is the function assertPathAllowed of the file src/Markdownify.ts. Executing a manipulation can lead to symlink following. The attack can only be executed locally. The pull request to fix this issue awaits acceptance.
References
Configurations
No configuration.
History
05 Jul 2026, 05:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-05 05:16
Updated : 2026-07-06 18:02
NVD link : CVE-2026-14699
Mitre link : CVE-2026-14699
CVE.ORG link : CVE-2026-14699
JSON object : View
Products Affected
No product.
