CVE-2026-15522
MEDIUMtugcantopaloglu godot-mcp run_project index.js validatePath path traversal
Title source: cnaDescription
A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build/index.js of the component run_project. The manipulation of the argument projectPath results in path traversal. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.0.0 addresses this issue. The patch is identified as eb63add552aa4bd9205395cf91b40654654a3cf2. It is suggested to upgrade the affected component.
References (8)
Core 8
Core References
Product product
https://github.com/tugcantopaloglu/godot-mcp/
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-377851 | tugcantopaloglu godot-mcp run_project index.js validatePath path traversal
https://vuldb.com/vuln/377851
Signature, Permissions Required signature
permissions-required
VDB-377851 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/377851/cti
Third Party Advisory third-party-advisory
CVE-2026-15522 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15522
Third Party Advisory third-party-advisory
Submit #854523 | tugcantopaloglu godot-mcp 2.0.0 Path Traversal
https://vuldb.com/submit/854523
Exploit exploit
issue-tracking
https://github.com/tugcantopaloglu/godot-mcp/issues/9
Scores
CVSS v3
5.3
EPSS
0.0014
EPSS Percentile
3.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (2)
tugcantopaloglu/godot-mcp
2.0.0
tugcantopaloglu/godot-mcp
3.0.0
Published
Jul 13, 2026
Tracked Since
Jul 13, 2026