CVE-2026-15522

MEDIUM

tugcantopaloglu godot-mcp run_project index.js validatePath path traversal

Title source: cna
STIX 2.1

Description

A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build/index.js of the component run_project. The manipulation of the argument projectPath results in path traversal. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.0.0 addresses this issue. The patch is identified as eb63add552aa4bd9205395cf91b40654654a3cf2. It is suggested to upgrade the affected component.

References (8)

Core 8
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-377851 | tugcantopaloglu godot-mcp run_project index.js validatePath path traversal
https://vuldb.com/vuln/377851
Signature, Permissions Required signature permissions-required
VDB-377851 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/377851/cti
Third Party Advisory third-party-advisory
CVE-2026-15522 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15522
Third Party Advisory third-party-advisory
Submit #854523 | tugcantopaloglu godot-mcp 2.0.0 Path Traversal
https://vuldb.com/submit/854523

Scores

CVSS v3 5.3
EPSS 0.0014
EPSS Percentile 3.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
tugcantopaloglu/godot-mcp 2.0.0
tugcantopaloglu/godot-mcp 3.0.0
Published Jul 13, 2026
Tracked Since Jul 13, 2026