← Terug naar overzicht

A path traversal vulnerability has been identified in dekdee adobe-xd-mcp version 1.0.0. The flaw exists in the file src/parsers/xd-parser.ts within the file-access-from-request endpoint. Attackers can manipulate the outputFile or outputDir arguments to traverse the file system beyond intended directories. The vulnerability can be exploited remotely, increasing its risk surface significantly. A public exploit is already available, raising the threat level for any exposed instances. The project maintainer was notified via a GitHub issue but has not responded or issued a patch. No workaround has been officially provided at this time. The combination of public exploit availability and lack of vendor response makes this a high-priority concern.

Affected products

  • dekdee adobe-xd-mcp 1.0.0

Related CVE's

  • CVE-2026-79622

Categories

  • Supply Chain & Dependencies
  • Web Technologies
  • Zero-Day Vulnerabilities