A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts. The manipulation leads to path traversal. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Mon, 25 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts. The manipulation leads to path traversal. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | debugmcp mcp-debugger server.ts handleGetSourceContext path traversal | |
| First Time appeared |
Debugmcp
Debugmcp mcp-debugger |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:debugmcp:mcp-debugger:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Debugmcp
Debugmcp mcp-debugger |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-25T14:45:09.859Z
Reserved: 2026-05-24T08:58:22.240Z
Link: CVE-2026-9467
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-25T16:30:16Z